Index: modules/search/search.module
===================================================================
RCS file: /cvs/drupal/drupal/modules/search/search.module,v
retrieving revision 1.358
diff -u -p -r1.358 search.module
--- modules/search/search.module	18 Aug 2010 18:40:50 -0000	1.358
+++ modules/search/search.module	25 Aug 2010 05:43:28 -0000
@@ -1029,7 +1029,15 @@ function search_box_form_submit($form, &
   $form_id = $form['form_id']['#value'];
   $info = search_get_default_module_info();
   if ($info) {
-    $form_state['redirect'] = 'search/' . $info['path'] . '/' . trim($form_state['values'][$form_id]);
+    // Prefer to append directly to the URL, but fall back if that isn't
+    // possible due to a ".." pattern in the search keys.
+    $keys = trim($form_state['values'][$form_id]);
+    if (!preg_match('%(?:^|/)\\.\\.(?:/|$)%', $keys)) {
+      $form_state['redirect'] = 'search/' . $info['path'] . '/' . $keys;
+    }
+    else {
+      $form_state['redirect'] = array('search/' . $info['path'], array('query' => array('keys' => $keys)));
+    }
   }
   else {
     form_set_error(NULL, t('Search is currently disabled.'), 'error');
Index: modules/search/search.pages.inc
===================================================================
RCS file: /cvs/drupal/drupal/modules/search/search.pages.inc,v
retrieving revision 1.23
diff -u -p -r1.23 search.pages.inc
--- modules/search/search.pages.inc	18 Aug 2010 18:40:50 -0000	1.23
+++ modules/search/search.pages.inc	25 Aug 2010 05:43:28 -0000
@@ -11,15 +11,19 @@
  *
  * @param $module
  *   Search module to use for the search.
- * @param $keys
- *   Keywords to use for the search.
  */
-function search_view($module = NULL, $keys = '') {
+function search_view($module = NULL) {
   $info = FALSE;
   $redirect = FALSE;
-  $keys = trim($keys);
-  // Also try to pull search keywords out of the $_REQUEST variable to
-  // support old GET format of searches for existing links.
+  if (count(arg()) > 2) {
+    $keys = trim(implode('/', array_slice(arg(), 2)));
+  }
+  else {
+    $keys = '';
+  }
+  // Also try to pull search keywords out of the $_REQUEST variable to support
+  // searches containing "..", and also for the old GET format of searches for
+  // existing links.
   if (!$keys && !empty($_REQUEST['keys'])) {
     $keys = trim($_REQUEST['keys']);
   }
@@ -149,6 +153,12 @@ function search_form_submit($form, &$for
     // Fall through to the form redirect.
   }
 
-  $form_state['redirect'] = $form_state['action'] . '/' . $keys;
-  return;
+  // Prefer to append directly to the URL, but fall back if that isn't possible
+  // due to a ".." pattern in the search keys.
+  if (!preg_match('%(?:^|/)\\.\\.(?:/|$)%', $keys)) {
+    $form_state['redirect'] = $form_state['action'] . '/' . $keys;
+  }
+  else {
+    $form_state['redirect'] = array($form_state['action'], array('query' => array('keys' => $keys)));
+  }
 }
