Public exploit · Metasploit Module
Measuresoft ScadaPro Remote Command Execution
Exploit summary
Remote attackers can execute arbitrary commands on Measuresoft ScadaPro 4.0.0 and earlier through directory traversal exploitation of the ‘xf’ (execute function) command. The vulnerability allows attackers to invoke system() from msvcrt.dll to deploy backdoors and achieve remote code execution.
Source & references