RSS   Vulnerabilities for 'Pear liveuser'   RSS

2006-02-23
 
CVE-2006-0869

CWE-Other
 

 
Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Repository (PEAR) LiveUser 0.16.8 and earlier allows remote attackers to determine file existence, and possibly delete arbitrary files with short pathnames or possibly read arbitrary files, via a .. (dot dot) in the store_id value of a cookie.

 

 >>> Vendor: PEAR 10 Products
Xml rpc
MAIL
PEAR
Text password
Pear liveuser
Pear archive tar
Pear archive zip
Structures datagrid datasource mdb2
Html ajax
Crypt gpg


Copyright 2024, cxsecurity.com

 

Back to Top