Arwen Cross Site Scripting & SQL Injection