A CWE-89:Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in U.motion Servers and Touch Panels (affected versions listed in the security notification) which could cause arbitrary code to be executed when a malicious command is entered.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Schneider-electric
Subscribe
|
Mtn6260-0310
Subscribe
Mtn6260-0310 Firmware
Subscribe
Mtn6260-0315
Subscribe
Mtn6260-0315 Firmware
Subscribe
Mtn6260-0410
Subscribe
Mtn6260-0410 Firmware
Subscribe
Mtn6260-0415
Subscribe
Mtn6260-0415 Firmware
Subscribe
Mtn6501-0001
Subscribe
Mtn6501-0001 Firmware
Subscribe
Mtn6501-0002
Subscribe
Mtn6501-0002 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-28625 | A CWE-89:Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in U.motion Servers and Touch Panels (affected versions listed in the security notification) which could cause arbitrary code to be executed when a malicious command is entered. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.se.com/ww/en/download/document/SEVD-2020-133-03/ |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: schneider
Published:
Updated: 2024-08-04T09:33:19.594Z
Reserved: 2020-01-21T00:00:00.000Z
Link: CVE-2020-7500
No data.
Status : Modified
Published: 2020-06-16T20:15:14.863
Modified: 2024-11-21T05:37:16.007
Link: CVE-2020-7500
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD