CVE-2006-0869
Last modified
CVE-2006-0869 is a vulnerability of currently unknown severity. Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Repository (PEAR) LiveUser 0.16.8 and earlier allows remote attackers to determine file existence, and possibly delete arbitrary files with short pathnames or possibly read arbitrary files, via a .. (dot dot) in the store_id value of a cookie.. EPSS estimates a 3.92% chance of exploitation in the next 30 days.
Description
Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Repository (PEAR) LiveUser 0.16.8 and earlier allows remote attackers to determine file existence, and possibly delete arbitrary files with short pathnames or possibly read arbitrary files, via a .. (dot dot) in the store_id value of a cookie.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pear | Pear Liveuser | 0.3 |
| Pear | Pear Liveuser | 0.5 |
| Pear | Pear Liveuser | 0.5.1 |
| Pear | Pear Liveuser | 0.6 |
| Pear | Pear Liveuser | 0.6.1 |
| Pear | Pear Liveuser | 0.7 |
| Pear | Pear Liveuser | 0.8 |
| Pear | Pear Liveuser | 0.8.1 |
| Pear | Pear Liveuser | 0.9 |
| Pear | Pear Liveuser | 0.10.0 |
| Pear | Pear Liveuser | 0.11.0 |
| Pear | Pear Liveuser | 0.11.1 |
| Pear | Pear Liveuser | 0.12.0 |
| Pear | Pear Liveuser | 0.13.0 |
| Pear | Pear Liveuser | 0.13.1 |
| Pear | Pear Liveuser | 0.13.2 |
| Pear | Pear Liveuser | 0.13.3 |
| Pear | Pear Liveuser | 0.14.0 |
| Pear | Pear Liveuser | 0.15.0 |
| Pear | Pear Liveuser | 0.15.1 |
| Pear | Pear Liveuser | 0.16.0 |
| Pear | Pear Liveuser | 0.16.1 |
| Pear | Pear Liveuser | 0.16.2 |
| Pear | Pear Liveuser | 0.16.3 |
| Pear | Pear Liveuser | 0.16.4 |
| Pear | Pear Liveuser | 0.16.5 |
| Pear | Pear Liveuser | 0.16.6 |
| Pear | Pear Liveuser | 0.16.7 |
| Pear | Pear Liveuser | 0.16.8 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-0869?
How severe is CVE-2006-0869?
How do I fix CVE-2006-0869?
Are you affected by CVE-2006-0869?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
