* XSS vulnerability in "Share Interface" (oC-SA-2013-029) * Authentication bypass in "user_webdavauth" (oC-SA-2013-030)