CVE-2006-6941 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 2.4% (pctl 83)
Patch early
A public exploit exists.
Description
index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to obtain sensitive information via an invalid action parameter in an info operation, which discloses the path in an error message.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 2.39% — more likely to be exploited than 83% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-01-19 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| freewebshop | freewebshop |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | FreeWebShop.org script 2.2.2 - Multiple Vulnerabilities | 2006-11-02 |
References
→ the Explorer · watch your stack · NVD