{"api_version":"1","generated_at":"2026-07-23T04:20:10+00:00","cve":"CVE-2007-4656","urls":{"html":"https://cve.report/CVE-2007-4656","api":"https://cve.report/api/cve/CVE-2007-4656.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-4656","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-4656"},"summary":{"title":"CVE-2007-4656","description":"backup-manager-upload in Backup Manager before 0.6.3 provides the FTP server hostname, username, and password as plaintext command line arguments during FTP uploads, which allows local users to obtain sensitive information by listing the process and its arguments, a different vulnerability than CVE-2007-2766.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-09-04 22:17:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-200","CWE-255","CWE-310","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.1","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.debian.org/security/2008/dsa-1518","name":"http://www.debian.org/security/2008/dsa-1518","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Debian -- Security Information -- DSA-1518-1 backup-manager","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=439392","name":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=439392","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"#439392 - backup-manager: password disclosure in backup uploads - Debian Bug report logs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/25503","name":"http://www.securityfocus.com/bid/25503","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Backup Manager FTP Server Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://bugzilla.backup-manager.org/cgi-bin/show_bug.cgi?id=173","name":"http://bugzilla.backup-manager.org/cgi-bin/show_bug.cgi?id=173","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://osvdb.org/37444","name":"http://osvdb.org/37444","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/29377","name":"http://secunia.com/advisories/29377","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Debian update for backup-manager - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/26657","name":"http://secunia.com/advisories/26657","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"About Secunia Research | Flexera","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1018639","name":"http://www.securitytracker.com/id?1018639","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Backup Manager Discloses the Upload Site's FTP Password to Local Users - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www2.backup-manager.org/Release063","name":"http://www2.backup-manager.org/Release063","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Release063 - BackupManager","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-4656","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-4656","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"4656","vulnerable":"1","versionEndIncluding":"0.6.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"backup_manager","cpe5":"backup_manager","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T15:01:09.927Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"26657","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26657"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=439392"},{"name":"25503","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/25503"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www2.backup-manager.org/Release063"},{"name":"29377","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/29377"},{"name":"1018639","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1018639"},{"name":"DSA-1518","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2008/dsa-1518"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://bugzilla.backup-manager.org/cgi-bin/show_bug.cgi?id=173"},{"name":"37444","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/37444"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-08-30T00:00:00.000Z","descriptions":[{"lang":"en","value":"backup-manager-upload in Backup Manager before 0.6.3 provides the FTP server hostname, username, and password as plaintext command line arguments during FTP uploads, which allows local users to obtain sensitive information by listing the process and its arguments, a different vulnerability than CVE-2007-2766."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2008-03-28T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"26657","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26657"},{"tags":["x_refsource_CONFIRM"],"url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=439392"},{"name":"25503","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/25503"},{"tags":["x_refsource_CONFIRM"],"url":"http://www2.backup-manager.org/Release063"},{"name":"29377","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/29377"},{"name":"1018639","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1018639"},{"name":"DSA-1518","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2008/dsa-1518"},{"tags":["x_refsource_CONFIRM"],"url":"http://bugzilla.backup-manager.org/cgi-bin/show_bug.cgi?id=173"},{"name":"37444","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/37444"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-4656","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"backup-manager-upload in Backup Manager before 0.6.3 provides the FTP server hostname, username, and password as plaintext command line arguments during FTP uploads, which allows local users to obtain sensitive information by listing the process and its arguments, a different vulnerability than CVE-2007-2766."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"26657","refsource":"SECUNIA","url":"http://secunia.com/advisories/26657"},{"name":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=439392","refsource":"CONFIRM","url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=439392"},{"name":"25503","refsource":"BID","url":"http://www.securityfocus.com/bid/25503"},{"name":"http://www2.backup-manager.org/Release063","refsource":"CONFIRM","url":"http://www2.backup-manager.org/Release063"},{"name":"29377","refsource":"SECUNIA","url":"http://secunia.com/advisories/29377"},{"name":"1018639","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1018639"},{"name":"DSA-1518","refsource":"DEBIAN","url":"http://www.debian.org/security/2008/dsa-1518"},{"name":"http://bugzilla.backup-manager.org/cgi-bin/show_bug.cgi?id=173","refsource":"CONFIRM","url":"http://bugzilla.backup-manager.org/cgi-bin/show_bug.cgi?id=173"},{"name":"37444","refsource":"OSVDB","url":"http://osvdb.org/37444"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-4656","datePublished":"2007-09-04T22:00:00.000Z","dateReserved":"2007-09-04T00:00:00.000Z","dateUpdated":"2024-08-07T15:01:09.927Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-09-04 22:17:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-200","CWE-255","CWE-310","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:backup_manager:backup_manager:*:*:*:*:*:*:*:*","versionEndIncluding":"0.6.2","matchCriteriaId":"D6949B83-7F51-4271-8394-AE8134D514DA"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"4656","Ordinal":"1","Title":"CVE-2007-4656","CVE":"CVE-2007-4656","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"4656","Ordinal":"1","NoteData":"backup-manager-upload in Backup Manager before 0.6.3 provides the FTP server hostname, username, and password as plaintext command line arguments during FTP uploads, which allows local users to obtain sensitive information by listing the process and its arguments, a different vulnerability than CVE-2007-2766.","Type":"Description","Title":"CVE-2007-4656"},{"CveYear":"2007","CveId":"4656","Ordinal":"2","NoteData":"2007-09-04","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"4656","Ordinal":"3","NoteData":"2008-03-28","Type":"Other","Title":"Modified"}]}}}