SialWeb CMS eCommerce versions 1.0 and 1.1 suffer from cross site scripting and remote SQL injection vulnerabilities.