CVE-2012-4951
Multiple SQL injection vulnerabilities in terminal/paramedit.aspx in VeriFone VeriCentre Web Console before 2.2 build 36 allow remote attackers to execute arbitrary SQL commands via the (1) TerminalId, (2) ModelName, or (3) ApplicationName parameter.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.52%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple SQL injection vulnerabilities in terminal/paramedit.aspx in VeriFone VeriCentre Web Console before 2.2 build 36 allow remote attackers to execute arbitrary SQL commands via the (1) TerminalId, (2) ModelName, or (3) ApplicationName parameter.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.52% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- verifone/vericentre web console
- Source
- cret@cert.org
References
- http://www.clearskies.net/documents/css-advisory-css1211-vericentre.pdfExploit
- http://www.kb.cert.org/vuls/id/180091US Government Resource
- http://www.securityfocus.com/bid/56409
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79832
- http://www.clearskies.net/documents/css-advisory-css1211-vericentre.pdfExploit
- http://www.kb.cert.org/vuls/id/180091US Government Resource
- http://www.securityfocus.com/bid/56409
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79832
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.