Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2002-1694


Vulnerability Score 5.0 5.0
CVE Id CVE-2002-1694
Last Modified 05 Sep 2008 04:31:16
Published 31 Dec 2002 12:00:00
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE



Microsoft Internet Information Server (IIS) 4.0 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow remote attackers to modify the log file contents while IIS is running.

Vulnerable Systems


  • Microsoft Internet Information Server 4.0

  • Microsoft Internet Information Server 5.0


XF - iis-modify-log(7919)

BID - 3888

Last Updated: 27 May 2016 10:37:26