[Bug 664505] New: VUL-0: calibre: XSS and file disclosure