CVE-2007-4656
published 2007-09-04CVE-2007-4656: backup-manager-upload in Backup Manager before 0.6.3 provides the FTP server hostname, username, and password as plaintext command line arguments during FTP…
PriorityP46low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.36%
29.1th percentile
backup-manager-upload in Backup Manager before 0.6.3 provides the FTP server hostname, username, and password as plaintext command line arguments during FTP uploads, which allows local users to obtain sensitive information by listing the process and its arguments, a different vulnerability than CVE-2007-2766.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| backup_manager | backup_manager | <= 0.6.2 | — |
| debian | backup-manager | < backup-manager 0.7.6-3 (bookworm) | backup-manager 0.7.6-3 (bookworm) |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv7.2HIGH
vendor_debian7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2007-4656: backup-manager - backup-manager-upload in Backup Manager before 0.6.3 provides the FTP server hos...
vendor_debian·2007·CVSS 7.2
CVE-2007-4656 [HIGH] CVE-2007-4656: backup-manager - backup-manager-upload in Backup Manager before 0.6.3 provides the FTP server hos...
backup-manager-upload in Backup Manager before 0.6.3 provides the FTP server hostname, username, and password as plaintext command line arguments during FTP uploads, which allows local users to obtain sensitive information by listing the process and its arguments, a different vulnerability than CVE-2007-2766.
Scope: local
bookworm: resolved (fixed in 0.7.6-3)
bullseye: resolved (fixed in 0.7.6-3)
forky: resolved (fixed in 0.7.6-3)
sid: resolved (fixed in 0.7.6-3)
trixie: resolved (fixed in 0.7.6-3)
GHSA
GHSA-78jp-pvx9-93px: backup-manager-upload in Backup Manager before 0
ghsa_unreviewed·2022-05-01·CVSS 7.2
CVE-2007-4656 [HIGH] CWE-200 GHSA-78jp-pvx9-93px: backup-manager-upload in Backup Manager before 0
backup-manager-upload in Backup Manager before 0.6.3 provides the FTP server hostname, username, and password as plaintext command line arguments during FTP uploads, which allows local users to obtain sensitive information by listing the process and its arguments, a different vulnerability than CVE-2007-2766.
OSV
CVE-2007-4656: backup-manager-upload in Backup Manager before 0
osv·2007-09-04·CVSS 7.2
CVE-2007-4656 [HIGH] CVE-2007-4656: backup-manager-upload in Backup Manager before 0
backup-manager-upload in Backup Manager before 0.6.3 provides the FTP server hostname, username, and password as plaintext command line arguments during FTP uploads, which allows local users to obtain sensitive information by listing the process and its arguments, a different vulnerability than CVE-2007-2766.
No detection rules found.
No writeups or analysis indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=439392http://bugzilla.backup-manager.org/cgi-bin/show_bug.cgi?id=173http://osvdb.org/37444http://secunia.com/advisories/26657http://secunia.com/advisories/29377http://www.debian.org/security/2008/dsa-1518http://www.securityfocus.com/bid/25503http://www.securitytracker.com/id?1018639http://www2.backup-manager.org/Release063http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=439392http://bugzilla.backup-manager.org/cgi-bin/show_bug.cgi?id=173http://osvdb.org/37444http://secunia.com/advisories/26657http://secunia.com/advisories/29377http://www.debian.org/security/2008/dsa-1518http://www.securityfocus.com/bid/25503http://www.securitytracker.com/id?1018639http://www2.backup-manager.org/Release063
2007-09-04
Published