← back
CVE-2006-0869

CVE-2006-0869

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 3.9%
from disclosure to weapon3650 days
Published on NVDFeb 23
1st PoC+3650d
exploitation probability
3.9%top 11% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Repository (PEAR) LiveUser 0.16.8 and earlier allows remote attackers to determine file existence, and possibly delete arbitrary files with short pathnames or possibly read arbitrary files, via a .. (dot dot) in the store_id value of a cookie.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.