PowerAward version 1.1.0 RC1 suffers from local file inclusion and cross site scripting vulnerabilities.