{"api_version":"1","generated_at":"2026-07-23T06:18:18+00:00","cve":"CVE-2007-4174","urls":{"html":"https://cve.report/CVE-2007-4174","api":"https://cve.report/api/cve/CVE-2007-4174.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-4174","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-4174"},"summary":{"title":"CVE-2007-4174","description":"Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers to modify the torrc configuration file, compromise anonymity, and have other unspecified impact via HTTP POST data containing commands without valid authentication, as demonstrated by an HTML form (1) hosted on a web site or (2) injected by a Tor exit node.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-08-07 10:17:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:N","baseScore":5.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securitytracker.com/id?1018510","name":"http://www.securitytracker.com/id?1018510","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Tor ControlPort Authentication Bug Lets Remote Users Modify the 'torrc' Configuration File - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/26301","name":"http://secunia.com/advisories/26301","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Tor ControlPort \"torrc\" Rewrite Vulnerability - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/2768","name":"http://www.vupen.com/english/advisories/2007/2768","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://archives.seul.org/or/announce/Aug-2007/msg00000.html","name":"http://archives.seul.org/or/announce/Aug-2007/msg00000.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Tor 0.1.2.16 is released","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/25188","name":"http://www.securityfocus.com/bid/25188","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Tor ControlPort Missing Authentication Unauthorized Access Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36407","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36407","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/36271","name":"http://osvdb.org/36271","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://archives.seul.org/or/announce/Sep-2007/msg00000.html","name":"http://archives.seul.org/or/announce/Sep-2007/msg00000.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Tor security advisory: cross-protocol http form attack","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35784","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35784","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-4174","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-4174","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"4174","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tor","cpe5":"tor","cpe6":"0.1.2.1","cpe7":"alpha","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"4174","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tor","cpe5":"tor","cpe6":"0.1.2.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"4174","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tor","cpe5":"tor","cpe6":"0.1.2.11","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"4174","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tor","cpe5":"tor","cpe6":"0.1.2.12","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"4174","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tor","cpe5":"tor","cpe6":"0.1.2.13","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"4174","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tor","cpe5":"tor","cpe6":"0.1.2.14","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"4174","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tor","cpe5":"tor","cpe6":"0.1.2.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"4174","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tor","cpe5":"tor","cpe6":"0.1.2.3","cpe7":"alpha","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"4174","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tor","cpe5":"tor","cpe6":"0.1.2.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"4174","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tor","cpe5":"tor","cpe6":"0.1.2.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"4174","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tor","cpe5":"tor","cpe6":"0.1.2.5","cpe7":"alpha","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"4174","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tor","cpe5":"tor","cpe6":"0.1.2.6","cpe7":"alpha","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"4174","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tor","cpe5":"tor","cpe6":"0.1.2.7","cpe7":"alpha","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"4174","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tor","cpe5":"tor","cpe6":"0.1.2.8","cpe7":"beta","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"4174","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tor","cpe5":"tor","cpe6":"0.1.2.9","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"4174","vulnerable":"1","versionEndIncluding":"0.1.2.15","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tor","cpe5":"tor","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T14:46:39.367Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"25188","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/25188"},{"name":"tor-control-command-execution(36407)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36407"},{"name":"1018510","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1018510"},{"name":"tor-controlport-security-bypass(35784)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35784"},{"name":"ADV-2007-2768","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/2768"},{"name":"36271","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/36271"},{"name":"26301","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26301"},{"name":"[or-announce] 20070901 Tor security advisory: cross-protocol http form attack","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://archives.seul.org/or/announce/Sep-2007/msg00000.html"},{"name":"[or-announce] 20070802 Tor 0.1.2.16 is released","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://archives.seul.org/or/announce/Aug-2007/msg00000.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-08-01T00:00:00.000Z","descriptions":[{"lang":"en","value":"Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers to modify the torrc configuration file, compromise anonymity, and have other unspecified impact via HTTP POST data containing commands without valid authentication, as demonstrated by an HTML form (1) hosted on a web site or (2) injected by a Tor exit node."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"25188","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/25188"},{"name":"tor-control-command-execution(36407)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36407"},{"name":"1018510","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1018510"},{"name":"tor-controlport-security-bypass(35784)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35784"},{"name":"ADV-2007-2768","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/2768"},{"name":"36271","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/36271"},{"name":"26301","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26301"},{"name":"[or-announce] 20070901 Tor security advisory: cross-protocol http form attack","tags":["mailing-list","x_refsource_MLIST"],"url":"http://archives.seul.org/or/announce/Sep-2007/msg00000.html"},{"name":"[or-announce] 20070802 Tor 0.1.2.16 is released","tags":["mailing-list","x_refsource_MLIST"],"url":"http://archives.seul.org/or/announce/Aug-2007/msg00000.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-4174","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers to modify the torrc configuration file, compromise anonymity, and have other unspecified impact via HTTP POST data containing commands without valid authentication, as demonstrated by an HTML form (1) hosted on a web site or (2) injected by a Tor exit node."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"25188","refsource":"BID","url":"http://www.securityfocus.com/bid/25188"},{"name":"tor-control-command-execution(36407)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36407"},{"name":"1018510","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1018510"},{"name":"tor-controlport-security-bypass(35784)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35784"},{"name":"ADV-2007-2768","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/2768"},{"name":"36271","refsource":"OSVDB","url":"http://osvdb.org/36271"},{"name":"26301","refsource":"SECUNIA","url":"http://secunia.com/advisories/26301"},{"name":"[or-announce] 20070901 Tor security advisory: cross-protocol http form attack","refsource":"MLIST","url":"http://archives.seul.org/or/announce/Sep-2007/msg00000.html"},{"name":"[or-announce] 20070802 Tor 0.1.2.16 is released","refsource":"MLIST","url":"http://archives.seul.org/or/announce/Aug-2007/msg00000.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-4174","datePublished":"2007-08-07T10:00:00.000Z","dateReserved":"2007-08-07T00:00:00.000Z","dateUpdated":"2024-08-07T14:46:39.367Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-08-07 10:17:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:N","baseScore":5.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:tor:tor:*:*:*:*:*:*:*:*","versionEndIncluding":"0.1.2.15","matchCriteriaId":"67A44A79-CE5A-44D7-A6E6-4E7A3AA1DA2C"},{"vulnerable":true,"criteria":"cpe:2.3:a:tor:tor:0.1.2.1:alpha:*:*:*:*:*:*","matchCriteriaId":"E149062A-F48E-4E99-8A3C-B32FFC922695"},{"vulnerable":true,"criteria":"cpe:2.3:a:tor:tor:0.1.2.2:*:*:*:*:*:*:*","matchCriteriaId":"A74A3860-1FE5-4A03-9C99-2646F1AF84A8"},{"vulnerable":true,"criteria":"cpe:2.3:a:tor:tor:0.1.2.3:alpha:*:*:*:*:*:*","matchCriteriaId":"4340AB16-25B5-4371-B490-6F2563268358"},{"vulnerable":true,"criteria":"cpe:2.3:a:tor:tor:0.1.2.4:*:*:*:*:*:*:*","matchCriteriaId":"EA145B1E-674C-4C79-93C0-BC24EC5F8CDB"},{"vulnerable":true,"criteria":"cpe:2.3:a:tor:tor:0.1.2.5:*:*:*:*:*:*:*","matchCriteriaId":"FCD8B5C4-C680-4DE2-9245-0A8F380C15E9"},{"vulnerable":true,"criteria":"cpe:2.3:a:tor:tor:0.1.2.5:alpha:*:*:*:*:*:*","matchCriteriaId":"9B671031-08A4-4B9D-B3DA-7D074D8BFAC1"},{"vulnerable":true,"criteria":"cpe:2.3:a:tor:tor:0.1.2.6:alpha:*:*:*:*:*:*","matchCriteriaId":"1A2098AF-763E-4F62-BBD9-A4C9AC411C3A"},{"vulnerable":true,"criteria":"cpe:2.3:a:tor:tor:0.1.2.7:alpha:*:*:*:*:*:*","matchCriteriaId":"1F3C6BA8-9ED9-42F8-9054-F94840E653E8"},{"vulnerable":true,"criteria":"cpe:2.3:a:tor:tor:0.1.2.8:beta:*:*:*:*:*:*","matchCriteriaId":"27D917E6-7E71-4B14-8881-C22755C6899B"},{"vulnerable":true,"criteria":"cpe:2.3:a:tor:tor:0.1.2.9:*:*:*:*:*:*:*","matchCriteriaId":"F22F7D60-BBAE-4951-B84C-C70BEB88B6F3"},{"vulnerable":true,"criteria":"cpe:2.3:a:tor:tor:0.1.2.10:*:*:*:*:*:*:*","matchCriteriaId":"72B2E210-F46F-4A86-A923-82599D0CFF8B"},{"vulnerable":true,"criteria":"cpe:2.3:a:tor:tor:0.1.2.11:*:*:*:*:*:*:*","matchCriteriaId":"2C0372D0-8181-4812-9741-70DC4C0AEA2E"},{"vulnerable":true,"criteria":"cpe:2.3:a:tor:tor:0.1.2.12:*:*:*:*:*:*:*","matchCriteriaId":"62E983BF-8D3F-4B20-A89A-BC324C5AD150"},{"vulnerable":true,"criteria":"cpe:2.3:a:tor:tor:0.1.2.13:*:*:*:*:*:*:*","matchCriteriaId":"EF4EC417-80F8-4B04-9176-3B9199662D29"},{"vulnerable":true,"criteria":"cpe:2.3:a:tor:tor:0.1.2.14:*:*:*:*:*:*:*","matchCriteriaId":"EFC7477A-5DDA-42A6-828E-A818CCF208B7"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"4174","Ordinal":"1","Title":"CVE-2007-4174","CVE":"CVE-2007-4174","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"4174","Ordinal":"1","NoteData":"Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers to modify the torrc configuration file, compromise anonymity, and have other unspecified impact via HTTP POST data containing commands without valid authentication, as demonstrated by an HTML form (1) hosted on a web site or (2) injected by a Tor exit node.","Type":"Description","Title":"CVE-2007-4174"},{"CveYear":"2007","CveId":"4174","Ordinal":"2","NoteData":"2007-08-07","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"4174","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}