Описание
The vulnerability exists within processing of editscript.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. A directory traversal vulnerability allows a caller with standard user privileges to write arbitrary php files anywhere in the web service directory tree.
Уязвимые конфигурации
Конфигурация 1Версия до 1.3.4 (исключая)
cpe:2.3:a:schneider-electric:u.motion_builder:*:*:*:*:*:*:*:*
EPSS
Процентиль: 64%
0.00459
Низкий
8 High
CVSS3
6 Medium
CVSS2
Дефекты
CWE-22
Связанные уязвимости
CVSS3: 8
github
больше 3 лет назад
The vulnerability exists within processing of editscript.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. A directory traversal vulnerability allows a caller with standard user privileges to write arbitrary php files anywhere in the web service directory tree.
EPSS
Процентиль: 64%
0.00459
Низкий
8 High
CVSS3
6 Medium
CVSS2
Дефекты
CWE-22