PolyPager versions 1.0rc2 and below suffer from SQL injection and cross site scripting vulnerabilities.