ZCMS 1.1 Cross Site Scripting / SQL Injection

ZCMS version 1.1 suffers from cross site scripting and remote SQL injection vulnerabilities.