CVE-2014-4858
26.07.2014, 11:11
Multiple SQL injection vulnerabilities in CWPLogin.aspx in Sabre AirCentre Crew products 2010.2.12.20008 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field.
| Vendor | Product | Version |
|---|---|---|
| sabreairlinesolutions | crew_management | 𝑥 ≤ 2010.2.12.20008 |
| sabreairlinesolutions | crew_operations | 𝑥 ≤ 2010.2.12.20008 |
| sabreairlinesolutions | crew_planning | 𝑥 ≤ 2010.2.12.20008 |
| sabreairlinesolutions | crew_services | 𝑥 ≤ 2010.2.12.20008 |
| sabreairlinesolutions | crew_training | 𝑥 ≤ 2010.2.12.20008 |
𝑥
= Vulnerable software versions