Description
PHP 5.2.0 and 4.4 allows local users to bypass safe_mode and open_basedir restrictions via a malicious path and a null byte before a ";" in a session_save_path argument, followed by an allowed path, which causes a parsing inconsistency in which PHP validates the allowed path but sets session.save_path to the malicious path.
Remediation
References
Related Vulnerabilities
MySQL CVE-2012-0493 Vulnerability (CVE-2012-0493)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-2356)
MyBB URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2018-10678)
WordPress 5.5.x Multiple Vulnerabilities (5.5 - 5.5.10)
Drupal Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2007-5593)