CVE-2007-2766
published 2007-05-18CVE-2007-2766: lib/backup-methods.sh in Backup Manager before 0.7.6 provides the MySQL password as a plaintext command line argument, which allows local users to obtain this…
PriorityP421high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.33%
26.1th percentile
lib/backup-methods.sh in Backup Manager before 0.7.6 provides the MySQL password as a plaintext command line argument, which allows local users to obtain this password by listing the process and its arguments, related to lib/backup-methods.sh.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| backup_manager | backup_manager | <= 0.6.2 | — |
| backup_manager | backup_manager | <= 0.7.5 | — |
| debian | backup-manager | < backup-manager 0.7.6-1 (bookworm) | backup-manager 0.7.6-1 (bookworm) |
| debian | backup-manager | < backup-manager 0.7.6-3 (bookworm) | backup-manager 0.7.6-3 (bookworm) |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w99m-9m8w-9wj5: lib/backup-methods
ghsa_unreviewed·2022-05-01
CVE-2007-2766 [HIGH] GHSA-w99m-9m8w-9wj5: lib/backup-methods
lib/backup-methods.sh in Backup Manager before 0.7.6 provides the MySQL password as a plaintext command line argument, which allows local users to obtain this password by listing the process and its arguments, related to lib/backup-methods.sh.
GHSA
GHSA-78jp-pvx9-93px: backup-manager-upload in Backup Manager before 0
ghsa_unreviewed·2022-05-01·CVSS 7.2
CVE-2007-4656 [HIGH] CWE-200 GHSA-78jp-pvx9-93px: backup-manager-upload in Backup Manager before 0
backup-manager-upload in Backup Manager before 0.6.3 provides the FTP server hostname, username, and password as plaintext command line arguments during FTP uploads, which allows local users to obtain sensitive information by listing the process and its arguments, a different vulnerability than CVE-2007-2766.
OSV
CVE-2007-4656: backup-manager-upload in Backup Manager before 0
osv·2007-09-04·CVSS 7.2
CVE-2007-4656 [HIGH] CVE-2007-4656: backup-manager-upload in Backup Manager before 0
backup-manager-upload in Backup Manager before 0.6.3 provides the FTP server hostname, username, and password as plaintext command line arguments during FTP uploads, which allows local users to obtain sensitive information by listing the process and its arguments, a different vulnerability than CVE-2007-2766.
OSV
CVE-2007-2766: lib/backup-methods
osv·2007-05-18·CVSS 7.2
CVE-2007-2766 [HIGH] CVE-2007-2766: lib/backup-methods
lib/backup-methods.sh in Backup Manager before 0.7.6 provides the MySQL password as a plaintext command line argument, which allows local users to obtain this password by listing the process and its arguments, related to lib/backup-methods.sh.
Debian
CVE-2007-2766: backup-manager - lib/backup-methods.sh in Backup Manager before 0.7.6 provides the MySQL password...
vendor_debian·2007·CVSS 7.2
CVE-2007-2766 [HIGH] CVE-2007-2766: backup-manager - lib/backup-methods.sh in Backup Manager before 0.7.6 provides the MySQL password...
lib/backup-methods.sh in Backup Manager before 0.7.6 provides the MySQL password as a plaintext command line argument, which allows local users to obtain this password by listing the process and its arguments, related to lib/backup-methods.sh.
Scope: local
bookworm: resolved (fixed in 0.7.6-1)
bullseye: resolved (fixed in 0.7.6-1)
forky: resolved (fixed in 0.7.6-1)
sid: resolved (fixed in 0.7.6-1)
trixie: resolved (fixed in 0.7.6-1)
Debian
CVE-2007-4656: backup-manager - backup-manager-upload in Backup Manager before 0.6.3 provides the FTP server hos...
vendor_debian·2007·CVSS 7.2
CVE-2007-4656 [HIGH] CVE-2007-4656: backup-manager - backup-manager-upload in Backup Manager before 0.6.3 provides the FTP server hos...
backup-manager-upload in Backup Manager before 0.6.3 provides the FTP server hostname, username, and password as plaintext command line arguments during FTP uploads, which allows local users to obtain sensitive information by listing the process and its arguments, a different vulnerability than CVE-2007-2766.
Scope: local
bookworm: resolved (fixed in 0.7.6-3)
bullseye: resolved (fixed in 0.7.6-3)
forky: resolved (fixed in 0.7.6-3)
sid: resolved (fixed in 0.7.6-3)
trixie: resolved (fixed in 0.7.6-3)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://bugzilla.backup-manager.org/cgi-bin/show_bug.cgi?id=146http://osvdb.org/34780http://www.backup-manager.org/pipermail/backup-manager-commits/2007-January/000212.htmlhttp://www.vupen.com/english/advisories/2007/2412http://www2.backup-manager.org/Release076https://exchange.xforce.ibmcloud.com/vulnerabilities/34489http://bugzilla.backup-manager.org/cgi-bin/show_bug.cgi?id=146http://osvdb.org/34780http://www.backup-manager.org/pipermail/backup-manager-commits/2007-January/000212.htmlhttp://www.vupen.com/english/advisories/2007/2412http://www2.backup-manager.org/Release076https://exchange.xforce.ibmcloud.com/vulnerabilities/34489
2007-05-18
Published