PT-2018-18164 · Weblog Expert · Weblog Expert Web Server Enterprise
Hyp3Rlinx
+1
·
Publicado
2018-03-09
·
Atualizado
2019-10-03
·
CVE-2018-7581
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WebLog Expert Web Server Enterprise version 9.4
Description
The issue concerns weak permissions in the
ProgramDataWebLog ExpertWebServerWebServer.cfg file, allowing local users to set a cleartext password and login as admin.Recommendations
For WebLog Expert Web Server Enterprise version 9.4, consider restricting access to the
WebServer.cfg file to prevent local users from modifying it and gaining admin access. As a temporary workaround, restrict the file permissions to prevent unauthorized modifications until a proper fix is applied.Exploit
Correção
Incorrect Permission
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Weblog Expert Web Server Enterprise