CVE-2014-4858

Multiple SQL injection vulnerabilities in CWPLogin.aspx in Sabre AirCentre Crew products 2010.2.12.20008 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
certccCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 64%
VendorProductVersion
sabreairlinesolutionscrew_management
𝑥
≤ 2010.2.12.20008
sabreairlinesolutionscrew_operations
𝑥
≤ 2010.2.12.20008
sabreairlinesolutionscrew_planning
𝑥
≤ 2010.2.12.20008
sabreairlinesolutionscrew_services
𝑥
≤ 2010.2.12.20008
sabreairlinesolutionscrew_training
𝑥
≤ 2010.2.12.20008
𝑥
= Vulnerable software versions