7.5
CVSSv2

CVE-2006-0868

Published: 23/02/2006 Updated: 18/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple unspecified injection vulnerabilities in unspecified Auth Container back ends for PEAR::Auth prior to 1.2.4, and 1.3.x prior to 1.3.0r4, allow remote malicious users to "falsify authentication credentials," related to the "underlying storage containers."

Vulnerable Product Search on Vulmon Subscribe to Product

pear xml rpc 1.0.2

pear xml rpc 1.0.3

pear xml rpc 1.2.0rc5

pear xml rpc 1.2.0rc6

pear xml rpc 1.0.4

pear xml rpc 1.1.0

pear xml rpc 1.2.0

pear xml rpc 1.2.0rc7

pear xml rpc 1.2.1

pear xml rpc 1.2.0rc3

pear xml rpc 1.2.0rc4

pear xml rpc 1.3.0rc2

pear xml rpc 1.3.0rc3

pear xml rpc 1.2.0rc1

pear xml rpc 1.2.0rc2

pear xml rpc 1.2.2

pear xml rpc 1.3.0rc1

Vendor Advisories

Debian Bug report logs - #354474 php-auth: [CVE-2006-0868] Multiple unspecified injection vulnerabilities Package: php-auth; Maintainer for php-auth is Debian PHP PEAR Maintainers <pkg-php-pear@listsaliothdebianorg>; Source for php-auth is src:php-auth (PTS, buildd, popcon) Reported by: Stefan Fritsch <sf@sfritschde&g ...