CVE-2007-6723
Severity CVSS v4.0:
Pending analysis
Type:
CWE-16
Configuration Errors
Publication date:
31/03/2009
Last modified:
17/08/2017
Description
TorK before 0.22, when running on Windows and Mac OS X, installs Privoxy with a configuration file (config.txt or config) that contains insecure (1) enable-remote-toggle and (2) enable-edit-actions settings, which allows remote attackers to bypass intended access restrictions and modify configuration.
Impact
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:anonymityanywhere:tork:0.22:*:*:*:*:*:*:* | ||
cpe:2.3:a:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://archives.seul.org/or/talk/Oct-2007/msg00291.html
- http://archives.seul.org/or/talk/Oct-2007/msg00296.html
- http://sourceforge.net/project/shownotes.php?release_id=551544&group_id=159836
- http://www.osvdb.org/48694
- http://www.securityfocus.com/bid/26386
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42280