Description
PHP 4.0 with cURL functions allows remote attackers to bypass the open_basedir setting and read arbitrary files via a file: URL argument to the curl_init function.
Remediation
References
Related Vulnerabilities
PHP CVE-2009-3293 Vulnerability (CVE-2009-3293)
WordPress Plugin Wordpress Picture/Portfolio/Media Gallery Server-Side Request Forgery (3.0.1)
Oracle Application Server Other Vulnerability (CVE-2002-0947)
WordPress Plugin External Links-nofollow, noopener & new window Cross-Site Scripting (2.55)
Jboss EAP Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2011-2487)