peter bassill · operator
$ cve CVE-2012-4951 JSON

CVE-2012-4951 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 1.5% (pctl 74)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in terminal/paramedit.aspx in VeriFone VeriCentre Web Console before 2.2 build 36 allow remote attackers to execute arbitrary SQL commands via the (1) TerminalId, (2) ModelName, or (3) ApplicationName parameter.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS1.52% — more likely to be exploited than 74% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2012-11-15
Last modified2026-06-16

Affected (1)

VendorProduct
verifonevericentre web console

Public exploits

SourceTitleDate
exploit-dbVeriCentre - Multiple SQL Injections2012-11-06

References

→ the Explorer  ·  watch your stack  ·  NVD