CVE-2008-6870

Merlix Educate Server - Information Disclosure via Direct Request to config.asp and users.asp

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-6870. PoCs published by ZoRLu.

AI-analyzed exploit summary This is a writeup describing multiple vulnerabilities in Merlix Educate Server, including authentication bypass and direct database download. No functional exploit code is provided.

Description

Merlix Educate Server allows remote attackers to bypass intended security restrictions and obtain sensitive information via a direct request to (1) config.asp and (2) users.asp.

Exploits (1)

exploitdb WRITEUP VERIFIED
by ZoRLu · textwebappsasp
https://www.exploit-db.com/exploits/7348

This is a writeup describing multiple vulnerabilities in Merlix Educate Server, including authentication bypass and direct database download. No functional exploit code is provided.

Classification
Writeup 90%
Attack Type
Auth Bypass | Info Leak
Complexity
Trivial
Reliability
Theoretical
Target: Merlix Educate Server
No auth needed
Prerequisites: network access to the target server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/47107
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/7348

Scores

EPSS 0.0273
EPSS Percentile 84.1%

Details

CWE
CWE-264
Status published
Products (1)
merlix/educate_server
Published Jul 23, 2009
Tracked Since Feb 18, 2026