CVE-2007-4656
Estado: ModificadaBaja (2.1)—
backup-manager-upload in Backup Manager before 0.6.3 provides the FTP server hostname, username, and password as plaintext command line arguments during FTP uploads, which allows local users to obtain sensitive information by listing the process and its arguments, a different vulnerability than CVE-2007-2766.
CVSS
- Versión: 2.0
- Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N
- Puntuación base: 2.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.36%
- Percentil entre todas las CVEs puntuadas: 28
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-200, CWE-255, CWE-310
Referencias
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=439392
- http://bugzilla.backup-manager.org/cgi-bin/show_bug.cgi?id=173
- http://osvdb.org/37444
- http://secunia.com/advisories/26657
- http://secunia.com/advisories/29377
- http://www.debian.org/security/2008/dsa-1518
- http://www.securityfocus.com/bid/25503
- http://www.securitytracker.com/id?1018639
- http://www2.backup-manager.org/Release063
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=439392
- http://bugzilla.backup-manager.org/cgi-bin/show_bug.cgi?id=173
- http://osvdb.org/37444
- http://secunia.com/advisories/26657
- http://secunia.com/advisories/29377
- http://www.debian.org/security/2008/dsa-1518
- http://www.securityfocus.com/bid/25503
- http://www.securitytracker.com/id?1018639
- http://www2.backup-manager.org/Release063
JSON original (NVD)
Mostrar
{
"id": "CVE-2007-4656",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.1,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-09-04T22:17:00.000",
"references": [
{
"url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=439392",
"source": "cve@mitre.org"
},
{
"url": "http://bugzilla.backup-manager.org/cgi-bin/show_bug.cgi?id=173",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/37444",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/26657",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/29377",
"source": "cve@mitre.org"
},
{
"url": "http://www.debian.org/security/2008/dsa-1518",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/25503",
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id?1018639",
"source": "cve@mitre.org"
},
{
"url": "http://www2.backup-manager.org/Release063",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=439392",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://bugzilla.backup-manager.org/cgi-bin/show_bug.cgi?id=173",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/37444",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/26657",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/29377",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.debian.org/security/2008/dsa-1518",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/25503",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1018639",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www2.backup-manager.org/Release063",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-200"
},
{
"lang": "en",
"value": "CWE-255"
},
{
"lang": "en",
"value": "CWE-310"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "backup-manager-upload in Backup Manager before 0.6.3 provides the FTP server hostname, username, and password as plaintext command line arguments during FTP uploads, which allows local users to obtain sensitive information by listing the process and its arguments, a different vulnerability than CVE-2007-2766."
},
{
"lang": "es",
"value": "backup-manager-upload de Backup Manager versiones anteriores a 0.6.3 proporciona el nombre de máquina, nombre del usuario y contraseña del servidor FTP, como argumentos de línea de comandos en texto plano durante la promoción FTP, lo cual permite a usuarios locales obtener información confidencial al listar el proceso y sus argumentos, vulnerabilidad distinta de CVE-2007-2766."
}
],
"lastModified": "2026-06-16T22:44:31.093",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:backup_manager:backup_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D6949B83-7F51-4271-8394-AE8134D514DA",
"versionEndIncluding": "0.6.2"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}