CVE-2006-0869
Summary
| CVE | CVE-2006-0869 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-02-23 23:02:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Repository (PEAR) LiveUser 0.16.8 and earlier allows remote attackers to determine file existence, and possibly delete arbitrary files with short pathnames or possibly read arbitrary files, via a .. (dot dot) in the store_id value of a cookie. |
Risk And Classification
Primary CVSS: v2.0 6.4 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:N
EPSS: 0.141770000 probability, percentile 0.943930000 (date 2026-04-16)
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Pear | Pear Liveuser | 0.10.0 | All | All | All |
| Application | Pear | Pear Liveuser | 0.11.0 | All | All | All |
| Application | Pear | Pear Liveuser | 0.11.1 | All | All | All |
| Application | Pear | Pear Liveuser | 0.12.0 | All | All | All |
| Application | Pear | Pear Liveuser | 0.13.0 | All | All | All |
| Application | Pear | Pear Liveuser | 0.13.1 | All | All | All |
| Application | Pear | Pear Liveuser | 0.13.2 | All | All | All |
| Application | Pear | Pear Liveuser | 0.13.3 | All | All | All |
| Application | Pear | Pear Liveuser | 0.14.0 | All | All | All |
| Application | Pear | Pear Liveuser | 0.15.0 | All | All | All |
| Application | Pear | Pear Liveuser | 0.15.1 | All | All | All |
| Application | Pear | Pear Liveuser | 0.16.0 | All | All | All |
| Application | Pear | Pear Liveuser | 0.16.1 | All | All | All |
| Application | Pear | Pear Liveuser | 0.16.2 | All | All | All |
| Application | Pear | Pear Liveuser | 0.16.3 | All | All | All |
| Application | Pear | Pear Liveuser | 0.16.4 | All | All | All |
| Application | Pear | Pear Liveuser | 0.16.5 | All | All | All |
| Application | Pear | Pear Liveuser | 0.16.6 | All | All | All |
| Application | Pear | Pear Liveuser | 0.16.7 | All | All | All |
| Application | Pear | Pear Liveuser | 0.16.8 | All | All | All |
| Application | Pear | Pear Liveuser | 0.3 | All | All | All |
| Application | Pear | Pear Liveuser | 0.5 | All | All | All |
| Application | Pear | Pear Liveuser | 0.5.1 | All | All | All |
| Application | Pear | Pear Liveuser | 0.6 | All | All | All |
| Application | Pear | Pear Liveuser | 0.6.1 | All | All | All |
| Application | Pear | Pear Liveuser | 0.7 | All | All | All |
| Application | Pear | Pear Liveuser | 0.8 | All | All | All |
| Application | Pear | Pear Liveuser | 0.8.1 | All | All | All |
| Application | Pear | Pear Liveuser | 0.9 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityReason | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| PEAR :: Package :: LiveUser | af854a3a-2127-422b-91ae-364da2661108 | pear.php.net | Patch |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| PEAR LiveUser Unauthorized File Access Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Contact Support | af854a3a-2127-422b-91ae-364da2661108 | www.gulftech.org | Vendor Advisory |
| SecurityTracker.com Archives - PEAR LiveUser Input Validation Flaws in Processing Cookies Let Remote Users Determine File Existence and Delete Files | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.