| From the Mandriva advisory:
* XSS due to unescaped HTML Output when executing a SQL query
(CVE-2013-4995).
* 5 XSS vulnerabilities in setup, chart display, process list, and
logo link. If a crafted version.json would be presented, an XSS could
be introduced (CVE-2013-4996).
* Full path disclosure vulnerabilities (CVE-2013-4998, CVE-2013-5000).
* Self-XSS due to unescaped HTML output in schema export
(CVE-2013-5002).
* SQL injection vulnerabilities, producing a privilege escalation
(control user) (CVE-2013-5003). |