CVE-2007-4656
Summary
| CVE | CVE-2007-4656 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-09-04 22:17:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | backup-manager-upload in Backup Manager before 0.6.3 provides the FTP server hostname, username, and password as plaintext command line arguments during FTP uploads, which allows local users to obtain sensitive information by listing the process and its arguments, a different vulnerability than CVE-2007-2766. |
Risk And Classification
Primary CVSS: v2.0 2.1 from [email protected]
AV:L/AC:L/Au:N/C:P/I:N/A:N
Problem Types: CWE-200 | CWE-255 | CWE-310 | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:L/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Backup Manager | Backup Manager | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian -- Security Information -- DSA-1518-1 backup-manager | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| #439392 - backup-manager: password disclosure in backup uploads - Debian Bug report logs | af854a3a-2127-422b-91ae-364da2661108 | bugs.debian.org | |
| Backup Manager FTP Server Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| bugzilla.backup-manager.org/cgi-bin/show_bug.cgi | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.backup-manager.org | |
| osvdb.org/37444 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Debian update for backup-manager - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| Backup Manager Discloses the Upload Site's FTP Password to Local Users - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Release063 - BackupManager | af854a3a-2127-422b-91ae-364da2661108 | www2.backup-manager.org | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.