Technote 7.2 suffers from the same remote file inclusion vulnerability as Technote 7.0. Obviously, the authors did not feel this was an important fix for the following release.
A remote blind SQL injection vulnerability has been discovered on the largest online diamond selling site, Surat Diamond. The owner was contacted by the author and does not care.