CVE-2012-4951: Verifone Vericentre Web Console
High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.
Multiple SQL injection vulnerabilities in terminal/paramedit.aspx in VeriFone VeriCentre Web Console before 2.2 build 36 allow remote attackers to execute arbitrary SQL commands via the (1) TerminalId, (2) ModelName, or (3) ApplicationName parameter.
Affected products
- Verifone Vericentre Web Console: up to and including 2.2; version 2.0 only; version 2.0.1 only
Published 2012-11-15. Last modified 2026-06-16.