Vulnerabilities > CVE-2005-1915 - Unspecified vulnerability in Log4Sh 1.2.3/1.2.4/1.2.5

047910
CVSS 2.1 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
local
low complexity
log4sh

Summary

The log4sh_readProperties function in log4sh 1.2.5 and earlier allows local users to overwrite arbitrary files via a symlink attack on predictable log4sh.$$ filenames.

Vulnerable Configurations

Part Description Count
Application
Log4Sh
3