The recent Flash Player vulnerability that's being used to steal WoW passwords is partly enabled by websites that are open to SQL injection vulnerabilities.
Details here:
http://www.shadowserver.org/wiki/pmwiki ... r.20080527
More general news articles:
http://blogs.zdnet.com/security/?p=1198
http://www.pcmag.com/article2/0,1895,2310320,00.asp
For end users, where to download updated player:
http://www.adobe.com/products/flashplayer/