CVE-2008-6870
Merlix Educate Server - Information Disclosure via Direct Request to config.asp and users.asp
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6870. PoCs published by ZoRLu.
AI-analyzed exploit summary This is a writeup describing multiple vulnerabilities in Merlix Educate Server, including authentication bypass and direct database download. No functional exploit code is provided.
Description
Merlix Educate Server allows remote attackers to bypass intended security restrictions and obtain sensitive information via a direct request to (1) config.asp and (2) users.asp.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by ZoRLu · textwebappsasp
https://www.exploit-db.com/exploits/7348
This is a writeup describing multiple vulnerabilities in Merlix Educate Server, including authentication bypass and direct database download. No functional exploit code is provided.
Classification
Writeup 90%
Attack Type
Auth Bypass | Info Leak
Complexity
Trivial
Reliability
Theoretical
Target:
Merlix Educate Server
No auth needed
Prerequisites:
network access to the target server
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/47107
Exploit, Third Party Advisory exploit
x_refsource_exploit-db
https://www.exploit-db.com/exploits/7348
Scores
EPSS
0.0273
EPSS Percentile
84.1%
Details
CWE
CWE-264
Status
published
Products (1)
merlix/educate_server
Published
Jul 23, 2009
Tracked Since
Feb 18, 2026