There seem to be some SQL injection vulnerabilities.
For example, /out.php?id=1'%20OR%201%20OR%20linkid='XXX will up the counts of all the links, once for each link present.
If this software is still being maintained, there are a number of changes I am looking at making to it for my own use - perhaps it would make sense to contribute some of them back.