Back
CVE-2006-0869
Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Repository (PEAR) LiveUser 0.16.8 and earlier allows remote attackers to determine file existence, and possibly delete arbitrary files with short pathnames or possibly read arbitrary files, via a .. (dot dot) in the store_id value of a cookie.
Published: Feb 23, 2006
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (29)
| Vendor | Product | Version |
|---|---|---|
| pear | pear_liveuser | 0.3 |
| pear | pear_liveuser | 0.5 |
| pear | pear_liveuser | 0.5.1 |
| pear | pear_liveuser | 0.6 |
| pear | pear_liveuser | 0.6.1 |
| pear | pear_liveuser | 0.7 |
| pear | pear_liveuser | 0.8 |
| pear | pear_liveuser | 0.8.1 |
| pear | pear_liveuser | 0.9 |
| pear | pear_liveuser | 0.10.0 |
| pear | pear_liveuser | 0.11.0 |
| pear | pear_liveuser | 0.11.1 |
| pear | pear_liveuser | 0.12.0 |
| pear | pear_liveuser | 0.13.0 |
| pear | pear_liveuser | 0.13.1 |
| pear | pear_liveuser | 0.13.2 |
| pear | pear_liveuser | 0.13.3 |
| pear | pear_liveuser | 0.14.0 |
| pear | pear_liveuser | 0.15.0 |
| pear | pear_liveuser | 0.15.1 |
…and 9 more
GitHub Security Advisory GHSA-3382-x3p8-5gv7
Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension...
References (18)
- http://pear.php.net/package/LiveUser/download/ Patch
- http://securityreason.com/securityalert/466
- http://securitytracker.com/id?1015659 Patch
- http://www.gulftech.org/?node=research&article_id=00103-02212006 Vendor Advisory
- http://www.securityfocus.com/archive/1/425711/100/0/threaded
- http://www.securityfocus.com/bid/16761
- http://www.vupen.com/english/advisories/2006/0697
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24852
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24853
- http://pear.php.net/package/LiveUser/download/ Patch
- http://securityreason.com/securityalert/466
- http://securitytracker.com/id?1015659 Patch
- http://www.gulftech.org/?node=research&article_id=00103-02212006 Vendor Advisory
- http://www.securityfocus.com/archive/1/425711/100/0/threaded
- http://www.securityfocus.com/bid/16761
Risk Scores
CVSS Score
6.4 / 10
EPSS Score
4.01%
Top 10% most likely to be exploited
Threat Score
26.8 / 100
Data Sources
NVD
EPSS
GitHub