Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-47fv-mm82-vwwx

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8

Описание

The vulnerability exists within processing of editscript.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. A directory traversal vulnerability allows a caller with standard user privileges to write arbitrary php files anywhere in the web service directory tree.

The vulnerability exists within processing of editscript.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. A directory traversal vulnerability allows a caller with standard user privileges to write arbitrary php files anywhere in the web service directory tree.

EPSS

Процентиль: 63%
0.00459
Низкий

8 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8
nvd
больше 7 лет назад

The vulnerability exists within processing of editscript.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. A directory traversal vulnerability allows a caller with standard user privileges to write arbitrary php files anywhere in the web service directory tree.

EPSS

Процентиль: 63%
0.00459
Низкий

8 High

CVSS3

Дефекты

CWE-22