ferretCMS 1.0.4-alpha Cross Site Scripting / SQL Injection

ferretCMS version 1.0.4-alpha suffers from cross site scripting and remote SQL injection vulnerabilities.