CVE-2006-0869
Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Repository (PEAR) LiveUser 0.16.8 and earlier allows remote attackers to determine file existence, and possibly delete arbitrary files with…
Does this matter?
Lower severity and a low EPSS score (4.01%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Repository (PEAR) LiveUser 0.16.8 and earlier allows remote attackers to determine file existence, and possibly delete arbitrary files with short pathnames or possibly read arbitrary files, via a .. (dot dot) in the store_id value of a cookie.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
- EPSS
- 4.01% probability · 90th percentile
- CISA KEV
- Not listed
- Affected
- pear/pear liveuser
- Source
- cve@mitre.org
References
- http://pear.php.net/package/LiveUser/download/Patch
- http://securityreason.com/securityalert/466
- http://securitytracker.com/id?1015659Patch
- http://www.gulftech.org/?node=research&article_id=00103-02212006Vendor Advisory
- http://www.securityfocus.com/archive/1/425711/100/0/threaded
- http://www.securityfocus.com/bid/16761
- http://www.vupen.com/english/advisories/2006/0697
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24852
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24853
- http://pear.php.net/package/LiveUser/download/Patch
- http://securityreason.com/securityalert/466
- http://securitytracker.com/id?1015659Patch
- http://www.gulftech.org/?node=research&article_id=00103-02212006Vendor Advisory
- http://www.securityfocus.com/archive/1/425711/100/0/threaded
- http://www.securityfocus.com/bid/16761
- http://www.vupen.com/english/advisories/2006/0697
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24852
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24853
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.