Schneider Electric U.Motion Builder是法国施耐德电气(Schneider Electric)公司的一套建筑物智能管理系统。 Schneider Electric U.Motion Builder 1.3.4及之前版本中的track_import_export.php脚本中存在操作系统命令注入漏洞,该漏洞源于外部输入数据构造操作系统可执行命令过程中,网络系统或产品未正确过滤其中的特殊字符、命令等。攻击者可利用该漏洞执行非法操作系统命令。
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| U.motion | U.motion Builder software version 1.3.4 | U.motion Builder software version 1.3.4 | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | U.motion Builder 1.3.4 contains a remote code execution vulnerability caused by improper input sanitization, allowing attackers to execute arbitrary system commands through crafted input parameters. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2018/CVE-2018-7841.yaml | POC详情 |
未找到公开 POC。
登录以生成 AI POCkatana