Vulnerabilities > Schneider Electric > U Motion Builder > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-07-03 CVE-2018-7787 Improper Input Validation vulnerability in Schneider-Electric U.Motion Builder 1.2.1
In Schneider Electric U.motion Builder software versions prior to v1.3.4, this vulnerability is due to improper validation of input of context parameter in HTTP GET request.
network
low complexity
schneider-electric CWE-20
5.3
2018-07-03 CVE-2018-7786 Cross-site Scripting vulnerability in Schneider-Electric U.Motion Builder 1.2.1
In Schneider Electric U.motion Builder software versions prior to v1.3.4, a cross site scripting (XSS) vulnerability exists which could allow injection of malicious scripts.
network
low complexity
schneider-electric CWE-79
6.1
2018-07-03 CVE-2018-7776 Information Exposure vulnerability in Schneider-Electric U.Motion Builder 1.2.1
The vulnerability exists within error.php in Schneider Electric U.motion Builder software versions prior to v1.3.4.
network
low complexity
schneider-electric CWE-200
4.3
2018-07-03 CVE-2018-7764 Path Traversal vulnerability in Schneider-Electric U.Motion Builder 1.2.1
The vulnerability exists within runscript.php applet in Schneider Electric U.motion Builder software versions prior to v1.3.4.
network
low complexity
schneider-electric CWE-22
4.3
2018-07-03 CVE-2018-7763 Path Traversal vulnerability in Schneider-Electric U.Motion Builder 1.2.1
The vulnerability exists within css.inc.php in Schneider Electric U.motion Builder software versions prior to v1.3.4.
network
low complexity
schneider-electric CWE-22
4.3
2017-09-26 CVE-2017-9960 Information Exposure vulnerability in Schneider-Electric U.Motion Builder 1.2.1
An information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system response to error provides more information than should be available to an unauthenticated user.
network
low complexity
schneider-electric CWE-200
5.3
2017-09-26 CVE-2017-9959 Unspecified vulnerability in Schneider-Electric U.Motion Builder 1.2.1
A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system accepts reboot in session from unauthenticated users, supporting a denial of service condition.
local
low complexity
schneider-electric
5.5