CVE-2007-6459

Anon Proxy Server 0.100, and probably 0.101, allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the host parameter to diagdns.php, and (2) the host parameter and possibly (3) the port parameter to diagconnect.php, a different vulnerability than CVE-2007-6460.
Configurations

Configuration 1 (hide)

cpe:2.3:a:anon_proxy_server:anon_proxy_server:0.100:*:*:*:*:*:*:*

History

21 Nov 2024, 00:40

Type Values Removed Values Added
References () http://osvdb.org/43711 - () http://osvdb.org/43711 -
References () http://osvdb.org/43712 - () http://osvdb.org/43712 -
References () http://securityreason.com/securityalert/3463 - () http://securityreason.com/securityalert/3463 -
References () http://www.securityfocus.com/archive/1/485151/100/0/threaded - () http://www.securityfocus.com/archive/1/485151/100/0/threaded -
References () http://www.securityfocus.com/bid/26882 - Exploit () http://www.securityfocus.com/bid/26882 - Exploit
References () https://www.exploit-db.com/exploits/4734 - () https://www.exploit-db.com/exploits/4734 -

Information

Published : 2007-12-20 00:46

Updated : 2024-11-21 00:40


NVD link : CVE-2007-6459

Mitre link : CVE-2007-6459

CVE.ORG link : CVE-2007-6459


JSON object : View

Products Affected

anon_proxy_server

  • anon_proxy_server
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')