Not safe enough for sql injection

Project:ProjectPier
Version:0.8.6-stable
Component:Code
Category:bug report
Priority:normal
Assigned:abhie
Status:patch - code needs review
Description

I have used ProjectPier for software development on campus, the developers are all interested students. Of course there are ignorant people who want to hack the system ProjectPier and they succeeded only in an easy way of sql injection ...

#1

Ah, they performed a pentest (penetration test). I will contact you off line for details to make PP more secure.

#2

Can you send me the info also?

Thanks in advance.

~dabehr

#3

I contacted abhie to get the details. Waiting for the answer.