2024-11-22 07:15:30 +00:00

170 lines
4.8 KiB
JSON

{
"id": "CVE-2007-4656",
"sourceIdentifier": "cve@mitre.org",
"published": "2007-09-04T22:17:00.000",
"lastModified": "2024-11-21T00:36:07.687",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "backup-manager-upload in Backup Manager before 0.6.3 provides the FTP server hostname, username, and password as plaintext command line arguments during FTP uploads, which allows local users to obtain sensitive information by listing the process and its arguments, a different vulnerability than CVE-2007-2766."
},
{
"lang": "es",
"value": "backup-manager-upload de Backup Manager versiones anteriores a 0.6.3 proporciona el nombre de m\u00e1quina, nombre del usuario y contrase\u00f1a del servidor FTP, como argumentos de l\u00ednea de comandos en texto plano durante la promoci\u00f3n FTP, lo cual permite a usuarios locales obtener informaci\u00f3n confidencial al listar el proceso y sus argumentos, vulnerabilidad distinta de CVE-2007-2766."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
"baseScore": 2.1,
"accessVector": "LOCAL",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"baseSeverity": "LOW",
"exploitabilityScore": 3.9,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-200"
},
{
"lang": "en",
"value": "CWE-255"
},
{
"lang": "en",
"value": "CWE-310"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:backup_manager:backup_manager:*:*:*:*:*:*:*:*",
"versionEndIncluding": "0.6.2",
"matchCriteriaId": "D6949B83-7F51-4271-8394-AE8134D514DA"
}
]
}
]
}
],
"references": [
{
"url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=439392",
"source": "cve@mitre.org"
},
{
"url": "http://bugzilla.backup-manager.org/cgi-bin/show_bug.cgi?id=173",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/37444",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/26657",
"source": "cve@mitre.org",
"tags": [
"Patch",
"Vendor Advisory"
]
},
{
"url": "http://secunia.com/advisories/29377",
"source": "cve@mitre.org"
},
{
"url": "http://www.debian.org/security/2008/dsa-1518",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/25503",
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id?1018639",
"source": "cve@mitre.org"
},
{
"url": "http://www2.backup-manager.org/Release063",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=439392",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://bugzilla.backup-manager.org/cgi-bin/show_bug.cgi?id=173",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/37444",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/26657",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Patch",
"Vendor Advisory"
]
},
{
"url": "http://secunia.com/advisories/29377",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.debian.org/security/2008/dsa-1518",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/25503",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1018639",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www2.backup-manager.org/Release063",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Patch"
]
}
]
}