Логотип exploitDog
bind:CVE-2007-4174
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2007-4174

Количество 4

Количество 4

ubuntu логотип

CVE-2007-4174

около 18 лет назад

Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers to modify the torrc configuration file, compromise anonymity, and have other unspecified impact via HTTP POST data containing commands without valid authentication, as demonstrated by an HTML form (1) hosted on a web site or (2) injected by a Tor exit node.

CVSS2: 5.8
EPSS: Средний
nvd логотип

CVE-2007-4174

около 18 лет назад

Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers to modify the torrc configuration file, compromise anonymity, and have other unspecified impact via HTTP POST data containing commands without valid authentication, as demonstrated by an HTML form (1) hosted on a web site or (2) injected by a Tor exit node.

CVSS2: 5.8
EPSS: Средний
debian логотип

CVE-2007-4174

около 18 лет назад

Tor before 0.1.2.16, when ControlPort is enabled, does not properly re ...

CVSS2: 5.8
EPSS: Средний
github логотип

GHSA-qprc-v4xr-fwgr

больше 3 лет назад

Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers to modify the torrc configuration file, compromise anonymity, and have other unspecified impact via HTTP POST data containing commands without valid authentication, as demonstrated by an HTML form (1) hosted on a web site or (2) injected by a Tor exit node.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2007-4174

Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers to modify the torrc configuration file, compromise anonymity, and have other unspecified impact via HTTP POST data containing commands without valid authentication, as demonstrated by an HTML form (1) hosted on a web site or (2) injected by a Tor exit node.

CVSS2: 5.8
17%
Средний
около 18 лет назад
nvd логотип
CVE-2007-4174

Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers to modify the torrc configuration file, compromise anonymity, and have other unspecified impact via HTTP POST data containing commands without valid authentication, as demonstrated by an HTML form (1) hosted on a web site or (2) injected by a Tor exit node.

CVSS2: 5.8
17%
Средний
около 18 лет назад
debian логотип
CVE-2007-4174

Tor before 0.1.2.16, when ControlPort is enabled, does not properly re ...

CVSS2: 5.8
17%
Средний
около 18 лет назад
github логотип
GHSA-qprc-v4xr-fwgr

Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers to modify the torrc configuration file, compromise anonymity, and have other unspecified impact via HTTP POST data containing commands without valid authentication, as demonstrated by an HTML form (1) hosted on a web site or (2) injected by a Tor exit node.

17%
Средний
больше 3 лет назад

Уязвимостей на страницу