PT-2018-18164 · Weblog Expert · Weblog Expert Web Server Enterprise
Hyp3Rlinx
+1
·
Published
2018-03-09
·
Updated
2019-10-03
·
CVE-2018-7581
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WebLog Expert Web Server Enterprise version 9.4
Description
The issue concerns weak permissions in the
ProgramDataWebLog ExpertWebServerWebServer.cfg file, allowing local users to set a cleartext password and login as admin.Recommendations
For WebLog Expert Web Server Enterprise version 9.4, consider restricting access to the
WebServer.cfg file to prevent local users from modifying it and gaining admin access. As a temporary workaround, restrict the file permissions to prevent unauthorized modifications until a proper fix is applied.Exploit
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Weblog Expert Web Server Enterprise