It was discovered that an internal variable is not properly sanitized before
being used to list directories. This can be exploited to list contents of
arbitrary directories. CVE-2010-0287
It was discovered that the ACL Manager plugin doesn't properly check the
administrator permissions. This allow an attacker to introduce arbitrary ACL rules and thus gaining access to a closed Wiki. CVE-2010-0288
It was discovered that the ACL Manager plugin doesn't have protections against cross-site request forgeries (CSRF). This can be exploited to change the access control rules by tricking a logged in administrator into visiting a malicious web site. CVE-2010-0289