SQL injection and some cross site scripting holes.