CVE-2008-6871

Merlix Educate Server - Unauthenticated Sensitive Information Exposure via Direct Request to db.mdb

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-6871. PoCs published by ZoRLu.

AI-analyzed exploit summary This is a writeup describing multiple vulnerabilities in Merlix Educate Server, including authentication bypass and direct database download. No functional exploit code is provided.

Description

Merlix Educate Server stores db.mdb under the web root with insufficient access control, which allows remote attackers to obtain unspecified sensitive information via a direct request.

Exploits (1)

exploitdb WRITEUP VERIFIED
by ZoRLu · textwebappsasp
https://www.exploit-db.com/exploits/7348

This is a writeup describing multiple vulnerabilities in Merlix Educate Server, including authentication bypass and direct database download. No functional exploit code is provided.

Classification
Writeup 90%
Attack Type
Auth Bypass | Info Leak
Complexity
Trivial
Reliability
Theoretical
Target: Merlix Educate Server
No auth needed
Prerequisites: network access to the target server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit vdb-entry x_refsource_osvdb
http://www.osvdb.org/50524
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33018
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/47108
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/7348

Scores

EPSS 0.0246
EPSS Percentile 82.3%

Details

CWE
CWE-264
Status published
Products (1)
merlix/educate_server
Published Jul 23, 2009
Tracked Since Feb 18, 2026