peter bassill · operator
$ cve CVE-2006-0869 JSON

CVE-2006-0869 EXPLOIT

6.4
MEDIUM · CVSS 2.0 · EPSS 4% (pctl 90)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Repository (PEAR) LiveUser 0.16.8 and earlier allows remote attackers to determine file existence, and possibly delete arbitrary files with short pathnames or possibly read arbitrary files, via a .. (dot dot) in the store_id value of a cookie.

Scoring

CVSS6.4 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
EPSS4.01% — more likely to be exploited than 90% of all CVEs
On CISA KEVno
Public exploityes
Published2006-02-23
Last modified2026-06-16

Affected (1)

VendorProduct
pearpear liveuser

Public exploits

SourceTitleDate
exploit-dbPEAR LiveUser < 0.16.8 - Arbitrary File Access2016-02-21

References

→ the Explorer  ·  watch your stack  ·  NVD