← Back

CVE-2014-4858

nvd nist
Published: Jul 26, 2014Modified: May 6, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Multiple SQL injection vulnerabilities in CWPLogin.aspx in Sabre AirCentre Crew products 2010.2.12.20008 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field.

Affected (5)

Crew Management
Crew Operations
Crew Planning
Crew Services
Crew Training
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2010.2.12.20008
Up to 2010.2.12.20008
Up to 2010.2.12.20008
Up to 2010.2.12.20008
Up to 2010.2.12.20008

References (4)

Source: cret@cert.org
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.