Time-based SQL injection exists in Spotweb 1.4.9 via the query string.
{ "ubuntu_priority": "medium" }