Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-6889. PoCs published by bd0rk.
AI-analyzed exploit summary This exploit describes an information disclosure vulnerability in fswiki 3.6.2 where the user.dat file is accessible without authentication, leading to password disclosure. The exploit provides a direct URL to access the sensitive file.
Description
FreeStyle Wiki (fswiki) 3.6.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct request for config/user.dat.
Exploits (1)
This exploit describes an information disclosure vulnerability in fswiki 3.6.2 where the user.dat file is accessible without authentication, leading to password disclosure. The exploit provides a direct URL to access the sensitive file.