There are input validation issues galore. Because AJAX moves application logic to the browser, there's a bigger attack surface.
AJAX represents the future of Web application technology. SPI Dynamics believes that by the end of 2006, 30 percent of all Web applications will be AJAX-based.