PT-2018-18164 · Weblog Expert · Weblog Expert Web Server Enterprise

Hyp3Rlinx

+1

·

Publicado

2018-03-09

·

Atualizado

2019-10-03

·

CVE-2018-7581

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WebLog Expert Web Server Enterprise version 9.4
Description The issue concerns weak permissions in the ProgramDataWebLog ExpertWebServerWebServer.cfg file, allowing local users to set a cleartext password and login as admin.
Recommendations For WebLog Expert Web Server Enterprise version 9.4, consider restricting access to the WebServer.cfg file to prevent local users from modifying it and gaining admin access. As a temporary workaround, restrict the file permissions to prevent unauthorized modifications until a proper fix is applied.

Exploit

Correção

Incorrect Permission

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-7581

Produtos afetados

Weblog Expert Web Server Enterprise