[Security-news] SA-CONTRIB-2009-011 Tasklist - SQL injection and Cross site scripting