Exploitation Summary
EIP tracks 2 public exploits for CVE-2011-3490. PoCs published by Metasploit.
AI-analyzed exploit summary This Metasploit module exploits a directory traversal vulnerability in Measuresoft ScadaPro to execute arbitrary commands via the 'xf' command, leveraging msvcrt.dll to upload and execute a backdoor.
Description
Multiple stack-based buffer overflows in service.exe in Measuresoft ScadaPro 4.0.0 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long command to port 11234, as demonstrated with the TF command.
Exploits (2)
This Metasploit module exploits a directory traversal vulnerability in Measuresoft ScadaPro to execute arbitrary commands via the 'xf' command, leveraging msvcrt.dll to upload and execute a backdoor.
This is a detailed technical analysis of multiple vulnerabilities in Measuresoft ScadaPro, including arbitrary command execution, directory traversal, and stack overflow vulnerabilities. The writeup includes disassembly snippets, opcode analysis, and proof-of-concept examples for exploitation.