aflog version 1.01 suffers from cross site scripting and SQL injection vulnerabilities in comments.php.