7.5
CVSSv2

CVE-2007-3997

Published: 04/09/2007 Updated: 26/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The (1) MySQL and (2) MySQLi extensions in PHP 4 prior to 4.4.8, and PHP 5 prior to 5.2.4, allow remote malicious users to bypass safe_mode and open_basedir restrictions via MySQL LOCAL INFILE operations, as demonstrated by a query with LOAD DATA LOCAL INFILE.

Vulnerable Product Search on Vulmon Subscribe to Product

php php

Exploits

Affected Products: <= PHP 523 <= PHP 447 Authors: Mattias Bengtsson <mattias@secwebse> Philip Olausson <po@secwebse> Reported: 2007-06-05 Released: 2007-08-30 CVE: CVE-2007-3997 Issue: A vulnerability exists in PHP's MySQL and MySQLi extenstions which can be used to bypass PHP's safe_mode security restriction Descrip ...