CVE-2007-4174
Published Aug 7, 2007
Last updated 7 years ago
Overview
- Description
- Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers to modify the torrc configuration file, compromise anonymity, and have other unspecified impact via HTTP POST data containing commands without valid authentication, as demonstrated by an HTML form (1) hosted on a web site or (2) injected by a Tor exit node.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5.8
- Impact score
- 4.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-264
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:tor:tor:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "67A44A79-CE5A-44D7-A6E6-4E7A3AA1DA2C", "versionEndIncluding": "0.1.2.15" }, { "criteria": "cpe:2.3:a:tor:tor:0.1.2.1:alpha:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E149062A-F48E-4E99-8A3C-B32FFC922695" }, { "criteria": "cpe:2.3:a:tor:tor:0.1.2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A74A3860-1FE5-4A03-9C99-2646F1AF84A8" }, { "criteria": "cpe:2.3:a:tor:tor:0.1.2.3:alpha:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4340AB16-25B5-4371-B490-6F2563268358" }, { "criteria": "cpe:2.3:a:tor:tor:0.1.2.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EA145B1E-674C-4C79-93C0-BC24EC5F8CDB" }, { "criteria": "cpe:2.3:a:tor:tor:0.1.2.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FCD8B5C4-C680-4DE2-9245-0A8F380C15E9" }, { "criteria": "cpe:2.3:a:tor:tor:0.1.2.5:alpha:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9B671031-08A4-4B9D-B3DA-7D074D8BFAC1" }, { "criteria": "cpe:2.3:a:tor:tor:0.1.2.6:alpha:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1A2098AF-763E-4F62-BBD9-A4C9AC411C3A" }, { "criteria": "cpe:2.3:a:tor:tor:0.1.2.7:alpha:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1F3C6BA8-9ED9-42F8-9054-F94840E653E8" }, { "criteria": "cpe:2.3:a:tor:tor:0.1.2.8:beta:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "27D917E6-7E71-4B14-8881-C22755C6899B" }, { "criteria": "cpe:2.3:a:tor:tor:0.1.2.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F22F7D60-BBAE-4951-B84C-C70BEB88B6F3" }, { "criteria": "cpe:2.3:a:tor:tor:0.1.2.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "72B2E210-F46F-4A86-A923-82599D0CFF8B" }, { "criteria": "cpe:2.3:a:tor:tor:0.1.2.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2C0372D0-8181-4812-9741-70DC4C0AEA2E" }, { "criteria": "cpe:2.3:a:tor:tor:0.1.2.12:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "62E983BF-8D3F-4B20-A89A-BC324C5AD150" }, { "criteria": "cpe:2.3:a:tor:tor:0.1.2.13:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EF4EC417-80F8-4B04-9176-3B9199662D29" }, { "criteria": "cpe:2.3:a:tor:tor:0.1.2.14:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EFC7477A-5DDA-42A6-828E-A818CCF208B7" } ], "operator": "OR" } ] } ]