CVE-2018-7581
HIGHWebLog Expert Web Server Enterprise 9.4 - Incorrect Permission Assignment for Critical Resource
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-7581. PoCs published by hyp3rlinx.
AI-analyzed exploit summary This advisory describes an authentication bypass vulnerability in WebLog Expert Web Server Enterprise v9.4 due to weak file permissions on 'WebServer.cfg', allowing local users to set a cleartext password and log in as admin.
Description
\ProgramData\WebLog Expert\WebServer\WebServer.cfg in WebLog Expert Web Server Enterprise 9.4 has weak permissions (BUILTIN\Users:(ID)C), which allows local users to set a cleartext password and login as admin.
Exploits (1)
This advisory describes an authentication bypass vulnerability in WebLog Expert Web Server Enterprise v9.4 due to weak file permissions on 'WebServer.cfg', allowing local users to set a cleartext password and log in as admin.
References (3)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H