6.8
CVSSv2

CVE-2007-6459

Published: 20/12/2007 Updated: 15/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Anon Proxy Server 0.100, and probably 0.101, allows remote malicious users to execute arbitrary commands via shell metacharacters in (1) the host parameter to diagdns.php, and (2) the host parameter and possibly (3) the port parameter to diagconnect.php, a different vulnerability than CVE-2007-6460.

Vulnerable Product Search on Vulmon Subscribe to Product

anon proxy server anon proxy server 0.100

Exploits

By Michael Brooks Vulnerability type: Multiple Remote System commands execution Software: Anon Proxy Server Home page:sourceforgenet/projects/anonproxyserver/ Affects version: 0100 Example exploit: 127001/anon_proxy_server_0100/diagdnsphp?host=googlecom%5C%27+%26%26+cat+%2Fetc%2Fpasswd+%23 A virtually identical flaw exists ...