SQL injection vulnerability in connection.php in Mediatheka 4.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter.Referenceshttp://securityreason.com/securityalert/4905http://www.securityfocus.com/bid/32836https://www.exploit-db.com/exploits/7476http://secunia.com/advisories/33176