[link|http://www.theinquirer.net/?article=23085|the Inquirer]:
According to Secunia, these involve cross scripting attacks involving IFRAME Javascript URLs and input passed to the IconURL parameter.
The holes have been confirmed in version 1.0.3, and exploit code is publicly available, said Secunia, in its note, [link|http://secunia.com/product/4227/|here]