vendor:
WebLog Expert Web Server Enterprise v9.4
by:
John Page (aka hyp3rlinx)
7.8
CVSS
HIGH
Authentication Bypass
CWE
Product Name: WebLog Expert Web Server Enterprise v9.4
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE: CVE-2018-7581
CPE:
Platforms Tested:
WebLog Expert Web Server Enterprise v9.4 Authentication Bypass
The "WebServer.cfg" file used by WebLog Expert Web Server Enterprise 9.4 has weak permissions, allowing local users to set a cleartext password and login as admin.