packetstormsecurity.com
http://packetstormsecurity.com/files/156184/Schneider-Electric-U.Motion-Builder-1.3.4-Command-Injection.html CVE-2018-7777
HIGH
Schneider Electric U.Motion Builder 1.3.4 - Authenticated Command Injection
Record summary
CVE-2018-7777 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
The vulnerability is due to insufficient handling of update_file request parameter on update_module.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. A remote, authenticated attacker can exploit this vulnerability by sending a crafted request to the target server.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | U.motion Builder Software, all versions prior to v1.3.4 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBSchneider Electric U.Motion Builder 1.3.4 - Authenticated Command InjectionExploitDB exploitby Cosmin CraciunNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-7777 schneider-electric.comConfirmation
https://www.schneider-electric.com/en/download/document/SEVD-2018-095-01