Mango Automation is a flexible SCADA, HMI And Automation software application that allows you to view, log, graph, animate, alarm, and report on data from sensors, equipment, PLCs, databases, webpages, etc. It is easy, affordable, and open source.
The application allows users to perform SQL queries via HTTP requests without performing any validity checks to verify the requests in sqlConsole.shtm page. This can be exploited to execute arbitrary SQL commands with administrative privileges if a logged-in user visits a malicious web site.