ECCMS 1.0 Cross Site Scripting / SQL Injection

ECCMS version 1.0 suffers from cross site scripting and remote SQL injection vulnerabilities.