CVE-2008-6871
Merlix Educate Server - Unauthenticated Sensitive Information Exposure via Direct Request to db.mdb
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6871. PoCs published by ZoRLu.
AI-analyzed exploit summary This is a writeup describing multiple vulnerabilities in Merlix Educate Server, including authentication bypass and direct database download. No functional exploit code is provided.
Description
Merlix Educate Server stores db.mdb under the web root with insufficient access control, which allows remote attackers to obtain unspecified sensitive information via a direct request.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by ZoRLu · textwebappsasp
https://www.exploit-db.com/exploits/7348
This is a writeup describing multiple vulnerabilities in Merlix Educate Server, including authentication bypass and direct database download. No functional exploit code is provided.
Classification
Writeup 90%
Attack Type
Auth Bypass | Info Leak
Complexity
Trivial
Reliability
Theoretical
Target:
Merlix Educate Server
No auth needed
Prerequisites:
network access to the target server
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (4)
Core 4
Core References
Exploit vdb-entry
x_refsource_osvdb
http://www.osvdb.org/50524
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/33018
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/47108
Exploit, Third Party Advisory exploit
x_refsource_exploit-db
https://www.exploit-db.com/exploits/7348
Scores
EPSS
0.0246
EPSS Percentile
82.3%
Details
CWE
CWE-264
Status
published
Products (1)
merlix/educate_server
Published
Jul 23, 2009
Tracked Since
Feb 18, 2026