index.php in the comments preview section in Textpattern (aka Txp CMS) 4.0.5 allows remote attackers to cause a denial of service via a long message parameter.
http://www.securityfocus.com/archive/1/487483/100/200/threaded
http://textpattern.com/weblog/310/textpattern-406-released