Will there be (is there now) a security patch for the SQL injection vulnerability in 1.0, 1.1, etc.? The FAQ suggests one will be available Real Soon Now. Version 1.2 doesn't mention it one way or the other. Having been bitten by the previous vulnerability I'm eager to patch as soon as possible.
AFAIK and can check the code the SQL injection flaw was fixed by Greg himself BUT never marked as fixed
I'll edit the faq asap
GauGau