NDBLOG 0.1 Cross Site Scripting / SQL Injection

NDBLOG version 0.1 suffers from cross site scripting and remote SQL injection vulnerabilities.