Vulnerabilities > Weblogexpert

DATE CVE VULNERABILITY TITLE RISK
2018-03-09 CVE-2018-7582 Allocation of Resources Without Limits or Throttling vulnerability in Weblogexpert Weblog Expert 9.4
WebLog Expert Web Server Enterprise 9.4 allows Remote Denial Of Service (daemon crash) via a long HTTP Accept Header to TCP port 9991.
network
low complexity
weblogexpert CWE-770
7.5
2018-03-09 CVE-2018-7581 Incorrect Permission Assignment for Critical Resource vulnerability in Weblogexpert Weblog Expert 9.4
\ProgramData\WebLog Expert\WebServer\WebServer.cfg in WebLog Expert Web Server Enterprise 9.4 has weak permissions (BUILTIN\Users:(ID)C), which allows local users to set a cleartext password and login as admin.
local
low complexity
weblogexpert CWE-732
7.8