6.4
CVSSv2

CVE-2006-0869

Published: 23/02/2006 Updated: 18/10/2018
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Repository (PEAR) LiveUser 0.16.8 and previous versions allows remote malicious users to determine file existence, and possibly delete arbitrary files with short pathnames or possibly read arbitrary files, via a .. (dot dot) in the store_id value of a cookie.

Vulnerable Product Search on Vulmon Subscribe to Product

pear pear liveuser 0.10.0

pear pear liveuser 0.13.3

pear pear liveuser 0.14.0

pear pear liveuser 0.15.0

pear pear liveuser 0.16.5

pear pear liveuser 0.16.6

pear pear liveuser 0.6.1

pear pear liveuser 0.7

pear pear liveuser 0.11.0

pear pear liveuser 0.11.1

pear pear liveuser 0.15.1

pear pear liveuser 0.16.0

pear pear liveuser 0.16.7

pear pear liveuser 0.16.8

pear pear liveuser 0.8

pear pear liveuser 0.8.1

pear pear liveuser 0.13.1

pear pear liveuser 0.13.2

pear pear liveuser 0.16.3

pear pear liveuser 0.16.4

pear pear liveuser 0.5.1

pear pear liveuser 0.6

pear pear liveuser 0.12.0

pear pear liveuser 0.13.0

pear pear liveuser 0.16.1

pear pear liveuser 0.16.2

pear pear liveuser 0.3

pear pear liveuser 0.5

pear pear liveuser 0.9

Exploits

PEAR LiveUser Arbitrary File Access Vendor: Markus Wolff Product: PEAR LiveUser Version: <= 0168 Website: pearphpnet/package/LiveUser/ BID: 16761 CVE: CVE-2006-0869 OSVDB: 23495 23496 PACKETSTORM: 44140 Description: LiveUser is a user authentication and permission management framework that is part of php's PEAR Library LiveUse ...