PT-2018-18164 · Weblog Expert · Weblog Expert Web Server Enterprise

Hyp3Rlinx

+1

·

Published

2018-03-09

·

Updated

2019-10-03

·

CVE-2018-7581

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WebLog Expert Web Server Enterprise version 9.4
Description The issue concerns weak permissions in the ProgramDataWebLog ExpertWebServerWebServer.cfg file, allowing local users to set a cleartext password and login as admin.
Recommendations For WebLog Expert Web Server Enterprise version 9.4, consider restricting access to the WebServer.cfg file to prevent local users from modifying it and gaining admin access. As a temporary workaround, restrict the file permissions to prevent unauthorized modifications until a proper fix is applied.

Exploit

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-7581

Affected Products

Weblog Expert Web Server Enterprise