Merlix Educate Server allows remote attackers to bypass intended security restrictions and obtain sensitive information via a direct request to (1) config.asp and (2) users.asp.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Educate_server | Merlix | - (including) | - (including) |
References