CVE-2012-4951
15.11.2012, 11:58
Multiple SQL injection vulnerabilities in terminal/paramedit.aspx in VeriFone VeriCentre Web Console before 2.2 build 36 allow remote attackers to execute arbitrary SQL commands via the (1) TerminalId, (2) ModelName, or (3) ApplicationName parameter.
Vendor | Product | Version |
---|---|---|
verifone | vericentre_web_console | 𝑥 ≤ 2.2 |
verifone | vericentre_web_console | 2.0 |
verifone | vericentre_web_console | 2.0.1 |
𝑥
= Vulnerable software versions
References