Multiple cross-site scripting (XSS) vulnerabilities in Webmin before 1.690 and Usermin before 1.600 allow remote attackers to inject arbitrary web script or HTML via vectors related to popup windows.
http://www.webmin.com/uchanges.html
http://www.webmin.com/changes.html
http://www.securitytracker.com/id/1030297
http://www.securitytracker.com/id/1030296
http://www.securityfocus.com/bid/67649
http://www.securityfocus.com/bid/67647