Safe Mode feature (safe_mode) in PHP 3.0 through 4.1.0 allows attackers with access to the MySQL database to bypass Safe Mode access restrictions and read arbitrary files using "LOAD DATA INFILE LOCAL" SQL statements.
Link | Tags |
---|---|
http://marc.info/?l=ntbugtraq&m=101303819613337&w=2 | mailing list |
http://marc.info/?l=ntbugtraq&m=101303065423534&w=2 | mailing list |
http://marc.info/?l=bugtraq&m=101304702002321&w=2 | mailing list |
http://marc.info/?l=bugtraq&m=101286577109716&w=2 | mailing list |
http://marc.info/?l=ntbugtraq&m=101285016125377&w=2 | mailing list |
http://www.iss.net/security_center/static/8105.php | vdb entry vendor advisory |
http://www.securityfocus.com/bid/4026 | vdb entry |