Softbiz Freelancers script version 1 suffers from cross site scripting and SQL injection vulnerabilities.