EIP-2026-107248

PRE-CVE

FreeWebShop 2.2.9 R2 - Multiple Remote Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-107248. PoCs published by Akita Software Security.

AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in FreeWebshop 2.2.9 R2, including SQL injection, session handling flaws, and brute-force password attacks. It includes functional code to enumerate customer IDs, brute-force passwords, and extract sensitive data via SQLi.

Description

FreeWebShop 2.2.9 R2 - Multiple Remote Vulnerabilities

Exploits (1)

exploitdb WORKING POC VERIFIED
by Akita Software Security · phpwebappsphp
https://www.exploit-db.com/exploits/33447

The exploit demonstrates multiple vulnerabilities in FreeWebshop 2.2.9 R2, including SQL injection, session handling flaws, and brute-force password attacks. It includes functional code to enumerate customer IDs, brute-force passwords, and extract sensitive data via SQLi.

Classification
Working Poc 90%
Attack Type
Sqli | Auth Bypass | Info Leak
Complexity
Moderate
Reliability
Reliable
Target: FreeWebshop.org 2.2.9 R2
No auth needed
Prerequisites: Access to the target web application · Network connectivity to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026