Home/Product/schneider electric u.motion builder
Product

schneider electric u.motion builder

24 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2018-7841
all versions
A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution
9.8CRITICAL
CVE-2018-7787
< 1.3.4
In Schneider Electric U.motion Builder software versions prior to v1.3.4, this vulnerability is due to improper validation of inpu
5.3MEDIUM
CVE-2018-7786
< 1.3.4
In Schneider Electric U.motion Builder software versions prior to v1.3.4, a cross site scripting (XSS) vulnerability exists which
6.1MEDIUM
CVE-2018-7785
< 1.3.4
In Schneider Electric U.motion Builder software versions prior to v1.3.4, a remote command injection allows authentication bypass.
9.8CRITICAL
CVE-2018-7777
< 1.3.4
The vulnerability is due to insufficient handling of update_file request parameter on update_module.php in Schneider Electric U.mo
8.8HIGH
CVE-2018-7776
< 1.3.4
The vulnerability exists within error.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. System informa
4.3MEDIUM
CVE-2018-7774
< 1.3.4
The vulnerability exists within processing of localize.php in Schneider Electric U.motion Builder software versions prior to v1.3.
8.8HIGH
CVE-2018-7773
< 1.3.4
The vulnerability exists within processing of nfcserver.php in Schneider Electric U.motion Builder software versions prior to v1.3
8.8HIGH
CVE-2018-7772
< 1.3.4
The vulnerability exists within processing of applets which are exposed on the web service in Schneider Electric U.motion Builder
8.8HIGH
CVE-2018-7771
< 1.3.4
The vulnerability exists within processing of editscript.php in Schneider Electric U.motion Builder software versions prior to v1.
8.0HIGH
CVE-2018-7769
< 1.3.4
The vulnerability exists within processing of xmlserver.php in Schneider Electric U.motion Builder software versions prior to v1.3
8.8HIGH
CVE-2018-7768
< 1.3.4
The vulnerability exists within processing of loadtemplate.php in Schneider Electric U.motion Builder software versions prior to v
8.8HIGH
CVE-2018-7767
< 1.3.4
The vulnerability exists within processing of editobject.php in Schneider Electric U.motion Builder software versions prior to v1.
8.8HIGH
CVE-2018-7766
< 1.3.4
The vulnerability exists within processing of track_getdata.php in Schneider Electric U.motion Builder software versions prior to
8.8HIGH
CVE-2018-7765
< 1.3.4
The vulnerability exists within processing of track_import_export.php in Schneider Electric U.motion Builder software versions pri
8.8HIGH
CVE-2018-7764
< 1.3.4
The vulnerability exists within runscript.php applet in Schneider Electric U.motion Builder software versions prior to v1.3.4. The
4.3MEDIUM
CVE-2018-7763
< 1.3.4
The vulnerability exists within css.inc.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The 'css' pa
4.3MEDIUM
CVE-2017-9960
<= 1.2.1
An information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which
5.3MEDIUM
CVE-2017-9959
<= 1.2.1
A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system accepts rebo
5.5MEDIUM
CVE-2017-9958
<= 1.2.1
An improper access control vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in whic
7.8HIGH
CVE-2017-9957
<= 1.2.1
A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the web service contain
9.8CRITICAL
CVE-2017-9956
<= 1.2.1
An authentication bypass vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which
7.3HIGH
CVE-2017-7974
<= 1.2.1
A path traversal information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and
9.8CRITICAL
CVE-2017-7973
<= 1.2.1
A SQL injection vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an unauth
9.8CRITICAL