CVE-2020-24841

CRITICAL

PNPSCADA 2.200816204020 - SQL Injection via 'interf' Parameter in browse.jsp

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-24841. PoCs published by İsmail ERKEK.

AI-analyzed exploit summary This exploit demonstrates an authenticated SQL injection vulnerability in PNPSCADA 2.200816204020 via the 'interf' parameter in /browse.jsp. It includes a time-based blind payload and instructions for using SQLmap to extract database information.

Description

PNPSCADA 2.200816204020 allows SQL injection via parameter 'interf' in /browse.jsp. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

Exploits (1)

exploitdb WORKING POC
by İsmail ERKEK · textwebappshardware
https://www.exploit-db.com/exploits/48757

This exploit demonstrates an authenticated SQL injection vulnerability in PNPSCADA 2.200816204020 via the 'interf' parameter in /browse.jsp. It includes a time-based blind payload and instructions for using SQLmap to extract database information.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: PNPSCADA 2.200816204020
Auth required
Prerequisites: Authenticated access to the application · Burpsuite or similar intercepting proxy · SQLmap for automated exploitation
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
http://sdg.com
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/48757

Scores

CVSS v3 9.8
EPSS 0.0176
EPSS Percentile 75.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
sdg/pnpscada 2.200816204020
Published Feb 16, 2021
Tracked Since Feb 18, 2026