MBLS Flex CMS 0.7.2 SQL Injection / Cross Site Scripting

MBLS Flex CMS version 0.7.2 suffers from remote SQL injection and cross site scripting vulnerabilities.