CVE-2012-2998

Trend Micro Control Manager <5.5.0.1823, <6.0.0.1449 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-2998. PoCs published by otoy.

AI-analyzed exploit summary This Python script exploits a time-based blind SQL injection vulnerability in Trend Micro Control Manager 5.5/6.0 via the AdHocQuery module. It extracts password hashes from the database by leveraging the 'id' parameter and measuring response delays.

Description

SQL injection vulnerability in the ad hoc query module in Trend Micro Control Manager (TMCM) before 5.5.0.1823 and 6.0 before 6.0.0.1449 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Exploits (1)

exploitdb WORKING POC VERIFIED
by otoy · pythonwebappswindows
https://www.exploit-db.com/exploits/21546

This Python script exploits a time-based blind SQL injection vulnerability in Trend Micro Control Manager 5.5/6.0 via the AdHocQuery module. It extracts password hashes from the database by leveraging the 'id' parameter and measuring response delays.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Trend Micro Control Manager 5.5/6.0
Auth required
Prerequisites: Valid session cookie (ASP_NET_SessionId, .ASPXAUTH, WFINFOR) · Network access to the target web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Patch third-party-advisory x_refsource_jvndb
http://jvndb.jvn.jp/jvndb/JVNDB-2012-000090
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1027584
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/950795
Patch third-party-advisory x_refsource_jvn
http://jvn.jp/en/jp/JVN42014489/index.html

Scores

EPSS 0.0609
EPSS Percentile 92.5%

Details

CWE
CWE-89
Status published
Products (9)
trend_micro/control_manager 2.0
trend_micro/control_manager 2.1
trend_micro/control_manager 2.5
trend_micro/control_manager 3.0 (2 CPE variants)
trend_micro/control_manager 3.5 (2 CPE variants)
trend_micro/control_manager 5.0 (2 CPE variants)
trend_micro/control_manager 5.5
trend_micro/control_manager 6.0
trend_micro/control_manager < 5.5
Published Sep 28, 2012
Tracked Since Feb 18, 2026