The (1) MySQL and (2) MySQLi extensions in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to bypass safe_mode and open_basedir restrictions via MySQL LOCAL INFILE operations, as demonstrated by a query with LOAD DATA LOCAL INFILE.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade php4Upgrade php5 | Dec 10, 2025 | Sep 11, 2007 |
| Gentoo Linux | — | Upgrade dev-lang/php. | Oct 30, 2017 | Sep 4, 2007 |
| Php | — | Upgrade to PHP version 5.2.4Upgrade to PHP version 4.4.8 | Oct 1, 2012 | Sep 4, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub