GQ File Manager 0.2.5 Cross Site Scripting / SQL Injection

GQ File Manager version 0.2.5 suffers from cross site scripting and remote SQL injection vulnerabilities.