Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

CVE-2014-4858

EPSS 1.31% · P67
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2014-4858

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Multiple SQL injection vulnerabilities in CWPLogin.aspx in Sabre AirCentre Crew products 2010.2.12.20008 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Sabre Airline Solutions Sabre AirCentre Crew SQL注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Sabre Airline Solutions Sabre AirCentre Crew是美国Sabre Airline Solutions公司的一套应用于运输行业的船员管理解决方案。该方案支持员工KPI制作和培训、业务流程培训和船员名册变更跟踪等。 Sabre Airline Solutions Sabre AirCentre Crew产品2010.2.12.20008及之前版本的CWPLogin.aspx脚本存在SQL注入漏洞。远程攻击者可借助‘username’或‘password’字段利用该漏洞执
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2014-4858

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2014-4858

登录查看更多情报信息。

Vendor Advisories for CVE-2014-4858 (2)

Same Patch Batch · n/a · 2014-07-26 · 15 CVEs total

CVE-2014-2625HP Network Virtualization 目录遍历漏洞
CVE-2014-2626HP Network Virtualization 目录遍历漏洞
CVE-2014-2966Caucho Resin Professional 安全漏洞
CVE-2014-4747IBM Sametime 安全漏洞
CVE-2014-4748IBM Sametime 跨站脚本漏洞
CVE-2014-4857Gurock Software Gurock TestRail 跨站脚本漏洞
CVE-2014-4971Microsoft Windows XP SP3 安全漏洞
CVE-2014-3071IBM InfoSphere Information Server 跨站脚本漏洞
CVE-2014-3301Cisco WebEx Meetings Server ProfileAction控制器安全漏洞
CVE-2014-3305Cisco WebEx Meetings Server Web框架跨站请求伪造漏洞
CVE-2014-3324Cisco TelePresence Server Management Interface 跨站脚本漏洞
CVE-2014-3326Cisco Security Manager SQL注入漏洞
CVE-2014-3328Cisco Unified Presence Server 安全漏洞
CVE-2014-4979Apple QuickTime 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2014-4858

No comments yet


Leave a comment