... The Apache HTTP Server provides very comprehensive and flexible logging capabilities. ... Anyone who can write to the directory where Apache is writing a log file can almost certainly gain access to the uid that the server is started as, which is normally root. ... In addition, log files may contain information supplied directly by the client, without escaping. ... Since it is possible to customize the access log, you can obtain more information about error conditions using that log file. ...
... Apache HTTP Server Version 2.2 . ... Error Log . Access Log . ... Other Log Files . Anyone who can write to the directory where Apache is writing a log file can almost certainly gain access to the uid that the server is started as, which is normally root. ... In addition, log files may contain information supplied directly by the client, without escaping. ... Since it is possible to customize the access log, you can obtain more information about error conditions using that log file. ...