Microsoft Internet Information Server (IIS) 4.0 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow remote attackers to modify the log file contents while IIS is running.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/3888 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/7919 | vdb entry |
http://online.securityfocus.com/archive/1/250591 | mailing list |