Description
PHP 4.0 with cURL functions allows remote attackers to bypass the open_basedir setting and read arbitrary files via a file: URL argument to the curl_init function.
Remediation
References
Related Vulnerabilities
OpenSSL Inadequate Encryption Strength Vulnerability (CVE-2020-1968)
IBMHttpServer Other Vulnerability (CVE-2000-1168)
WordPress Plugin All-in-One WP Migration Multiple Cross-Site Request Forgery Vulnerabilities (7.1)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-9848)