Agahi 1.6 Cross Site Scripting / SQL Injection

Agahi version 1.6 suffers from cross site scripting and remote SQL injection vulnerabilities.