Back

CVE-2006-0869

Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Repository (PEAR) LiveUser 0.16.8 and earlier allows remote attackers to determine file existence, and possibly delete arbitrary files with short pathnames or possibly read arbitrary files, via a .. (dot dot) in the store_id value of a cookie.

Published: Feb 23, 2006 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (29)

Vendor Product Version
pear pear_liveuser 0.3
pear pear_liveuser 0.5
pear pear_liveuser 0.5.1
pear pear_liveuser 0.6
pear pear_liveuser 0.6.1
pear pear_liveuser 0.7
pear pear_liveuser 0.8
pear pear_liveuser 0.8.1
pear pear_liveuser 0.9
pear pear_liveuser 0.10.0
pear pear_liveuser 0.11.0
pear pear_liveuser 0.11.1
pear pear_liveuser 0.12.0
pear pear_liveuser 0.13.0
pear pear_liveuser 0.13.1
pear pear_liveuser 0.13.2
pear pear_liveuser 0.13.3
pear pear_liveuser 0.14.0
pear pear_liveuser 0.15.0
pear pear_liveuser 0.15.1

…and 9 more

GitHub Security Advisory GHSA-3382-x3p8-5gv7

Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension...

Risk Scores

CVSS Score 6.4 / 10
EPSS Score 4.01%

Top 10% most likely to be exploited

Threat Score 26.8 / 100

Data Sources

NVD EPSS GitHub