Record summary

CVE-2018-7777 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.

Description

The vulnerability is due to insufficient handling of update_file request parameter on update_module.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. A remote, authenticated attacker can exploit this vulnerability by sending a crafted request to the target server.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE ListU.motion Builder Software, all versions prior to v1.3.4affected

Proofs of concept

1

Catalogued exploits

ExploitDBSchneider Electric U.Motion Builder 1.3.4 - Authenticated Command InjectionExploitDB exploitby Cosmin CraciunNot analyzed1 file
ExploitDB

PoC details

References

3