Files
CVEs-PoC/2012/CVE-2012-3022.md
2025-09-29 21:09:30 +02:00

769 B

CVE-2012-3022

Description

The SaveToFile method in a certain ActiveX control in TrendDisplay.dll in Canary Labs TrendLink 9.0.2.27051 and earlier does not properly restrict the creation of files, which allows remote attackers to download an arbitrary program onto a client machine, and execute this program, via a crafted web site.

POC

Reference

No PoCs from references.

Github