Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-5626

Опубликовано: 23 окт. 2007
Источник: nvd
CVSS3: 5.5
CVSS2: 2.1
EPSS Низкий

Описание

make_catalog_backup in Bacula 2.2.5, and probably earlier, sends a MySQL password as a command line argument, and sometimes transmits cleartext e-mail containing this command line, which allows context-dependent attackers to obtain the password by listing the process and its arguments, or by sniffing the network.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:bacula:bacula:*:*:*:*:*:*:*:*
Версия до 2.2.5 (включая)

EPSS

Процентиль: 8%
0.00034
Низкий

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-319

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 18 лет назад

make_catalog_backup in Bacula 2.2.5, and probably earlier, sends a MySQL password as a command line argument, and sometimes transmits cleartext e-mail containing this command line, which allows context-dependent attackers to obtain the password by listing the process and its arguments, or by sniffing the network.

CVSS3: 5.5
debian
почти 18 лет назад

make_catalog_backup in Bacula 2.2.5, and probably earlier, sends a MyS ...

CVSS3: 5.5
github
больше 3 лет назад

make_catalog_backup in Bacula 2.2.5, and probably earlier, sends a MySQL password as a command line argument, and sometimes transmits cleartext e-mail containing this command line, which allows context-dependent attackers to obtain the password by listing the process and its arguments, or by sniffing the network.

EPSS

Процентиль: 8%
0.00034
Низкий

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-319