When using re-colorable themes, color inputs are not sanitized. Malicious color values can be used to insert arbitrary CSS and script code. Successful exploitation requires the "Administer themes" permission.
This issue affects Drupal 6.x and 7.x.
Vendor Status:
Drupal issued an update for this vulnerability