CVE-2007-4656
backup-manager-upload in Backup Manager before 0.6.3 provides the FTP server hostname, username, and password as plaintext command line arguments during FTP uploads, which allows local users to obtain sensitive information by listing the process and its…
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
backup-manager-upload in Backup Manager before 0.6.3 provides the FTP server hostname, username, and password as plaintext command line arguments during FTP uploads, which allows local users to obtain sensitive information by listing the process and its arguments, a different vulnerability than CVE-2007-2766.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.36% probability · 30th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200, CWE-255, CWE-310
- Affected
- backup manager/backup manager
- Source
- cve@mitre.org
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=439392
- http://bugzilla.backup-manager.org/cgi-bin/show_bug.cgi?id=173
- http://osvdb.org/37444
- http://secunia.com/advisories/26657Patch, Vendor Advisory
- http://secunia.com/advisories/29377
- http://www.debian.org/security/2008/dsa-1518
- http://www.securityfocus.com/bid/25503
- http://www.securitytracker.com/id?1018639
- http://www2.backup-manager.org/Release063Patch
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=439392
- http://bugzilla.backup-manager.org/cgi-bin/show_bug.cgi?id=173
- http://osvdb.org/37444
- http://secunia.com/advisories/26657Patch, Vendor Advisory
- http://secunia.com/advisories/29377
- http://www.debian.org/security/2008/dsa-1518
- http://www.securityfocus.com/bid/25503
- http://www.securitytracker.com/id?1018639
- http://www2.backup-manager.org/Release063Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.