In Infodraw Media Relay Service (MRS) 7.1.0.0, the MRS web server (on port 12654) allows reading arbitrary files via ../ directory traversal in the username field. Reading ServerParameters.xml may reveal administrator credentials in cleartext or with MD5 hashing.

ESET Threat Reseach

Through the years, ESET and its researchers have been credited with many discoveries and have scored accolades for many of their research works.