LinuxSecurity.com: Cross-site scripting (XSS) vulnerability in functions.php in the default theme in WordPress allows remote authenticated administrators to inject arbitrary web script or HTML via the PATH_INFO (REQUEST_URI) to wp-admin/themes.php.
Original Source: http://www.linuxsecurity.com/content/view/134788?rdf