7.5
CVSSv2

CVE-2002-0229

Published: 16/05/2002 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 765
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Safe Mode feature (safe_mode) in PHP 3.0 up to and including 4.1.0 allows attackers with access to the MySQL database to bypass Safe Mode access restrictions and read arbitrary files using "LOAD DATA INFILE LOCAL" SQL statements.

Vulnerable Product Search on Vulmon Subscribe to Product

php php 3.0.13

php php 3.0.16

php php 3.0.8

php php 3.0.9

php php 4.1.0

php php 4.1.2

php php 3.0.1

php php 3.0.10

php php 3.0.4

php php 3.0.5

php php 4.0.3

php php 4.0.4

php php 3.0.11

php php 3.0.12

php php 3.0.6

php php 3.0.7

php php 4.0.5

php php 4.0.6

php php 3.0

php php 3.0.2

php php 3.0.3

php php 4.0

php php 4.0.1

Exploits

<?php /* source: wwwsecurityfocuscom/bid/4026/info PHP's 'safe_mode' feature may be used to restrict access to certain areas of a filesystem by PHP scripts However, a problem has been discovered that may allow an attacker to bypass these restrictions to gain unauthorized access to areas of the filesystem that are restricted when PHP ...
<?php /* source: wwwsecurityfocuscom/bid/4026/info PHP's 'safe_mode' feature may be used to restrict access to certain areas of a filesystem by PHP scripts However, a problem has been discovered that may allow an attacker to bypass these restrictions to gain unauthorized access to areas of the filesystem that are restricted when PHP ...
<?php /* source: wwwsecurityfocuscom/bid/4026/info PHP's 'safe_mode' feature may be used to restrict access to certain areas of a filesystem by PHP scripts However, a problem has been discovered that may allow an attacker to bypass these restrictions to gain unauthorized access to areas of the filesystem that are restricted when PHP ...