755
VMScore

CVE-2018-7841

Published: 22/05/2019 Updated: 23/05/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper set of characters is entered.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

schneider-electric u.motion builder 1.3.4

Exploits

RCE Security Advisory wwwrcesecuritycom 1 ADVISORY INFORMATION ======================= Product: Schneider Electric UMotion Builder Vendor URL: wwwschneider-electriccom Type: OS Command Injection [CWE-78] Date found: 2018-11-15 Date published: 2019-05-13 CVSSv3 Score: 98 (CVSS:30/AV:N/AC:L/PR:N/UI:N/S:U/C ...
Schneider Electric UMotion Builder version 134 suffers from an unauthenticated command injection vulnerability in track_import_exportphp ...