SQL injection vulnerability in view/objectDetail.php in Project'Or RIA 3.4.0 allows remote attackers to execute arbitrary SQL commands via the objectId parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/88584
http://secunia.com/advisories/55451
http://projectorria.org/index.php/menu_download_en/menu_history_en
http://archives.neohapsis.com/archives/fulldisclosure/2013-11/0031.html