Public exploit · Metasploit Module

Measuresoft ScadaPro Remote Command Execution

Published Rocco Calvi

Exploit summary

Remote attackers can execute arbitrary commands on Measuresoft ScadaPro 4.0.0 and earlier through directory traversal exploitation of the ‘xf’ (execute function) command. The vulnerability allows attackers to invoke system() from msvcrt.dll to deploy backdoors and achieve remote code execution.

Source & references