Exploitation Summary
EIP tracks 1 public exploit for CVE-2018-7777. PoCs published by Cosmin Craciun.
AI-analyzed exploit summary This exploit leverages an authenticated command injection vulnerability in Schneider Electric U.Motion Builder 1.3.4. It allows an attacker to execute arbitrary commands, including a reverse shell, by manipulating the file upload functionality in the update_module.php endpoint.
Description
The vulnerability is due to insufficient handling of update_file request parameter on update_module.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. A remote, authenticated attacker can exploit this vulnerability by sending a crafted request to the target server.
Exploits (1)
This exploit leverages an authenticated command injection vulnerability in Schneider Electric U.Motion Builder 1.3.4. It allows an attacker to execute arbitrary commands, including a reverse shell, by manipulating the file upload functionality in the update_module.php endpoint.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H