CVE-2012-4951 Information

Description

Multiple SQL injection vulnerabilities in terminal/paramedit.aspx in VeriFone VeriCentre Web Console before 2.2 build 36 allow remote attackers to execute arbitrary SQL commands via the (1) TerminalId (2) ModelName or (3) ApplicationName parameter.

Reference

http://www.clearskies.net/documents/css-advisory-css1211-vericentre.pdf http://www.kb.cert.org/vuls/id/180091 http://www.securityfocus.com/bid/56409 https://exchange.xforce.ibmcloud.com/vulnerabilities/79832

Share on: