Various pages within the control panel appear to have no input sanitation at all, and are passing unsantized values directly into various queries.