Back to search
CVE-2007-4174
Published: Aug 7, 2007
Modified: Aug 7, 2024
PUBLISHED
Description
Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers to modify the torrc configuration file, compromise anonymity, and have other unspecified impact via HTTP POST data containing commands without valid authentication, as demonstrated by an HTML form (1) hosted on a web site or (2) injected by a Tor exit node.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
25188
vdb-entry
x_refsource_BID
tor-control-command-execution(36407)
vdb-entry
x_refsource_XF
1018510
vdb-entry
x_refsource_SECTRACK
tor-controlport-security-bypass(35784)
vdb-entry
x_refsource_XF
ADV-2007-2768
vdb-entry
x_refsource_VUPEN
36271
vdb-entry
x_refsource_OSVDB
26301
third-party-advisory
x_refsource_SECUNIA
[or-announce] 20070901 Tor security advisory: cross-protocol http form attack
mailing-list
x_refsource_MLIST
[or-announce] 20070802 Tor 0.1.2.16 is released
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now