CVE-2007-4174

N/A Unknown
Published: August 07, 2007 Modified: April 23, 2026
View on NVD

Description

Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers to modify the torrc configuration file, compromise anonymity, and have other unspecified impact via HTTP POST data containing commands without valid authentication, as demonstrated by an HTML form (1) hosted on a web site or (2) injected by a Tor exit node.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://osvdb.org/36271
Source: cve@mitre.org
http://secunia.com/advisories/26301
Source: cve@mitre.org
Vendor Advisory
http://www.vupen.com/english/advisories/2007/2768
Source: cve@mitre.org
Vendor Advisory
http://archives.seul.org/or/announce/Aug-2007/msg00000.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://archives.seul.org/or/announce/Sep-2007/msg00000.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/36271
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/26301
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://www.securityfocus.com/bid/25188
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securitytracker.com/id?1018510
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2007/2768
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/35784
Source: af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/36407
Source: af854a3a-2127-422b-91ae-364da2661108

18 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
19.1%
95th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

tor