← Back

CVE-2006-0869

nvd nist
Published: Feb 23, 2006Modified: Apr 16, 2026

JSON object

Loading...
6.4
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:N
Exploitability: 10.0 / Impact: 4.9
Source: NVD

Description

Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Repository (PEAR) LiveUser 0.16.8 and earlier allows remote attackers to determine file existence, and possibly delete arbitrary files with short pathnames or possibly read arbitrary files, via a .. (dot dot) in the store_id value of a cookie.

Affected (29)

Products: Pear: Pear Liveuser
1 product
Pear Liveuser
Configuration A
29 vulnerable
Vulnerable SoftwareAffected Versions
Pear
Version 0.10.0
Version 0.11.0
Version 0.11.1
Version 0.12.0
Version 0.13.0
Version 0.13.1
Version 0.13.2
Version 0.13.3
Version 0.14.0
Version 0.15.0
Version 0.15.1
Version 0.16.0
Version 0.16.1
Version 0.16.2
Version 0.16.3
Version 0.16.4
Version 0.16.5
Version 0.16.6
Version 0.16.7
Version 0.16.8
Version 0.3
Version 0.5.1
Version 0.5
Version 0.6.1
Version 0.6
Version 0.7
Version 0.8.1
Version 0.8
Version 0.9

References (18)

Source: cve@mitre.org
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.