Files
CVEs-PoC/2014/CVE-2014-2956.md
T
2025-09-29 21:09:30 +02:00

809 B

CVE-2014-2956

Description

ScriptHelperApi in the AVG ScriptHelper ActiveX control in ScriptHelper.exe in AVG Secure Search toolbar before 18.1.7.598 and AVG Safeguard before 18.1.7.644 does not implement domain-based access control for method calls, which allows remote attackers to trigger the downloading and execution of arbitrary programs via a crafted web site.

POC

Reference

Github

No PoCs found on GitHub currently.