Input validation holes in Member Management System version 2.1 allow for SQL injection and cross site scripting attacks.