wp-login.php in WordPress allows remote attackers to redirect authenticated users to other websites and potentially obtain sensitive information via the redirect_to parameter.Referenceshttp://www.metaeye.org/advisories/40http://secunia.com/advisories/30960http://www.securityfocus.com/archive/1/463291/100/0/threadedhttp://www.debian.org/security/2008/dsa-1601