CVE-2006-0869
N/A
N/A
Summary
Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Repository (PEAR) LiveUser 0.16.8 and earlier allows remote attackers to determine file existence, and possibly delete arbitrary files with short pathnames or possibly read arbitrary files, via a .. (dot dot) in the store_id value of a cookie.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://pear.php.net/package/LiveUser/download/
- http://securitytracker.com/id?1015659
- http://www.securityfocus.com/bid/16761
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24853
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24852
- http://www.securityfocus.com/archive/1/425711/100/0/threaded
- http://securityreason.com/securityalert/466
- http://www.vupen.com/english/advisories/2006/0697
- http://www.gulftech.org/?node=research&article_id=00103-02212006
References
- http://pear.php.net/package/LiveUser/download/
- http://securitytracker.com/id?1015659
- http://www.securityfocus.com/bid/16761
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24853
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24852
- http://www.securityfocus.com/archive/1/425711/100/0/threaded
- http://securityreason.com/securityalert/466
- http://www.vupen.com/english/advisories/2006/0697
- http://www.gulftech.org/?node=research&article_id=00103-02212006
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.