Whoops! Fixed an SQL injection vulnerability in the CLI installer. (Not like it's a huge deal because the vulnerability was only introduced last commit and if you make it to that stage you already know the database password)
ALTER TABLE users ADD COLUMN password_salt varchar(40) NOT NULL DEFAULT '';