Mango Automation is a flexible SCADA, HMI And Automation software application that allows you to view, log, graph, animate, alarm, and report on data from sensors, equipment, PLCs, databases, webpages, etc. It is easy, affordable, and open source.
The POST parameter 'c0-param0' in the testProcessCommand.dwr method is not properly sanitised before being used to execute commands. This can be exploited to inject and execute arbitrary OS commands as well as using cross-site request forgery attacks.