cpe:/a:mediatheka:mediatheka:4.2 CVE-2008-5895 2009-01-12T15:00:02.577-05:00 2017-09-28T21:32:52.137-04:00 7.5 NETWORK LOW NONE PARTIAL PARTIAL PARTIAL http://nvd.nist.gov 2009-01-12T16:55:00.000-05:00 ALLOWS_OTHER_ACCESS BID 32836 SECUNIA 33176 SREASON 4905 EXPLOIT-DB 7476 SQL injection vulnerability in connection.php in Mediatheka 4.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter.