CVE-2014-4858

EUVD-2014-4777
Multiple SQL injection vulnerabilities in CWPLogin.aspx in Sabre AirCentre Crew products 2010.2.12.20008 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 64%
Affected Products (NVD)
VendorProductVersion
sabreairlinesolutionscrew_management
𝑥
≤ 2010.2.12.20008
sabreairlinesolutionscrew_operations
𝑥
≤ 2010.2.12.20008
sabreairlinesolutionscrew_planning
𝑥
≤ 2010.2.12.20008
sabreairlinesolutionscrew_services
𝑥
≤ 2010.2.12.20008
sabreairlinesolutionscrew_training
𝑥
≤ 2010.2.12.20008
𝑥
= Vulnerable software versions