Gentoo Linux Security Advisory GLSA 200701-10 – When decoding trackbacks with alternate character sets, WordPress does not correctly sanitize the entries before further modifying a SQL query. WordPress also displays different error messages in wp-login.php based upon whether or not a user exists. David Kierznowski has discovered that WordPress fails to properly sanitize recent file information in /wp-admin/templates.php before sending that information to a browser. Versions less than 2.0.6 are affected.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/53697/glsa-200701-10.txt
Source: https://packetstormsecurity.com/files/53697/Gentoo-Linux-Security-Advisory-200701-10.html

