ZenPhoto 1.4.8 XSS / SQL Injection / Traversal

ZenPhoto version 1.4.8 suffers from cross site scripting, remote SQL injection, and path traversal vulnerabilities.