SQL injection vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to execute arbitrary SQL commands via a crafted SOAP message.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2012-3010
http://www.us-cert.gov/control_systems/pdf/ICSA-12-256-01.pdf