CVE-2006-0932
https://notcve.org/view.php?id=CVE-2006-0932
Directory traversal vulnerability in zip.lib.php 0.1.1 in PEAR::Archive_Zip allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a ZIP archive. • http://securityreason.com/securityalert/486 http://www.hamid.ir/security/phpzip.txt http://www.securityfocus.com/archive/1/425967/100/0/threaded http://www.securityfocus.com/archive/1/426153/100/0/threaded https://exchange.xforce.ibmcloud.com/vulnerabilities/24972 •
CVE-2006-0868
https://notcve.org/view.php?id=CVE-2006-0868
Multiple unspecified injection vulnerabilities in unspecified Auth Container back ends for PEAR::Auth before 1.2.4, and 1.3.x before 1.3.0r4, allow remote attackers to "falsify authentication credentials," related to the "underlying storage containers." • http://pear.php.net/package/Auth/download/1.2.4 http://pear.php.net/package/Auth/download/1.3.0r4 http://secunia.com/advisories/19008 http://secunia.com/advisories/19301 http://securitytracker.com/id?1015666 http://www.gentoo.org/security/en/glsa/glsa-200603-13.xml http://www.securityfocus.com/archive/1/425796/100/0/threaded http://www.securityfocus.com/bid/16758 http://www.vupen.com/english/advisories/2006/0696 https://exchange.xforce.ibmcloud.com/vulnerabilities •
CVE-2006-0869 – PEAR LiveUser < 0.16.8 - Arbitrary File Access
https://notcve.org/view.php?id=CVE-2006-0869
Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Repository (PEAR) LiveUser 0.16.8 and earlier allows remote attackers to determine file existence, and possibly delete arbitrary files with short pathnames or possibly read arbitrary files, via a .. (dot dot) in the store_id value of a cookie. • https://www.exploit-db.com/exploits/43834 http://pear.php.net/package/LiveUser/download http://securityreason.com/securityalert/466 http://securitytracker.com/id?1015659 http://www.gulftech.org/?node=research&article_id=00103-02212006 http://www.securityfocus.com/archive/1/425711/100/0/threaded http://www.securityfocus.com/bid/16761 http://www.vupen.com/english/advisories/2006/0697 https://exchange.xforce.ibmcloud.com/vulnerabilities/24852 https://exchange.xforce.ibmcloud.com/vulnerabili •
CVE-2005-4730
https://notcve.org/view.php?id=CVE-2005-4730
Unspecified vulnerability in PEAR Text_Password 1.0 has unknown impact and attack vectors, related to "problematic seeding" of the random number generator, possibly predictable seeds. • http://pear.php.net/package/Text_Password/download http://www.osvdb.org/23825 •