CVE-2018-7841
CRITICAL KEV NUCLEIU.motion Builder <1.3.4 - SQL Injection
Title source: llmExploitation Summary
CVE-2018-7841 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added April 15, 2022. EIP tracks 1 public exploit from researchers including Julien Ahrens. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates an unauthenticated OS command injection vulnerability in Schneider Electric U.Motion Builder via the 'object_id' parameter in 'track_import_export.php'. The PoC shows a 10-second sleep command injection, confirming arbitrary command execution.
Description
A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper set of characters is entered.
Exploits (1)
This exploit demonstrates an unauthenticated OS command injection vulnerability in Schneider Electric U.Motion Builder via the 'object_id' parameter in 'track_import_export.php'. The PoC shows a 10-second sleep command injection, confirming arbitrary command execution.
Nuclei Templates (1)
http.headers_hash:1985490094
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H