CVE-2008-6870
Merlix Educate Server - Access Control
Title source: ruleDescription
Merlix Educate Server allows remote attackers to bypass intended security restrictions and obtain sensitive information via a direct request to (1) config.asp and (2) users.asp.
Exploits (1)
Scores
EPSS
0.0192
EPSS Percentile
83.1%
Classification
CWE
CWE-264
Status
draft
Affected Products (1)
merlix/educate_server
Timeline
Published
Jul 23, 2009
Tracked Since
Feb 18, 2026