MySQL AB Eventum versions 1.5.5 and below suffer from cross site scripting and SQL injection attacks.