PEAR LiveUser Unauthorized File Access Vulnerability
BID:16761
Info
PEAR LiveUser Unauthorized File Access Vulnerability
| Bugtraq ID: | 16761 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 21 2006 12:00AM |
| Updated: | Feb 23 2006 05:32PM |
| Credit: | James Bercegay of the GulfTech Security Research Team is credited with the discovery of this vulnerability. |
| Vulnerable: |
PEAR PEAR::LiveUser 0.16.8 |
| Not Vulnerable: |
PEAR PEAR::LiveUser 0.16.9 |
Discussion
PEAR LiveUser Unauthorized File Access Vulnerability
LiveUser is prone to an unauthorized file-access vulnerability. This issue is due to a failure in the package to properly sanitize user-supplied input.
An attacker can exploit this issue to delete arbitrary files in the context of the webserver process and confirm the existence of arbitrary files.
LiveUser is prone to an unauthorized file-access vulnerability. This issue is due to a failure in the package to properly sanitize user-supplied input.
An attacker can exploit this issue to delete arbitrary files in the context of the webserver process and confirm the existence of arbitrary files.
Exploit / POC
PEAR LiveUser Unauthorized File Access Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
PEAR LiveUser Unauthorized File Access Vulnerability
Solution:
The vendor has released an update to address this issue. Please see the referenced vendor advisory for further information.
PEAR PEAR::LiveUser 0.16.8
Solution:
The vendor has released an update to address this issue. Please see the referenced vendor advisory for further information.
PEAR PEAR::LiveUser 0.16.8
-
PEAR LiveUser-0.16.9.tgz
http://pear.php.net/get/LiveUser-0.16.9.tgz
References
PEAR LiveUser Unauthorized File Access Vulnerability
References:
References:
- PEAR LiveUser File Access Vulnerabilities (GulfTech Security)
- LiveUser Changelog (LiveUser)
- LiveUser Homepage (PEAR)