Description
The MySQL extension in PHP 5.2.4 and earlier allows remote attackers to bypass safe_mode and open_basedir restrictions via the MySQL (1) LOAD_FILE, (2) INTO DUMPFILE, and (3) INTO OUTFILE functions, a different issue than CVE-2007-3997.
Remediation
References
Related Vulnerabilities
WordPress Plugin Student Result or Employee Database Security Bypass (1.6.3)
WordPress Plugin Read Offline Cross-Site Scripting (0.9.17)
WordPress Plugin SAML SP Single Sign On-SSO login Cross-Site Scripting (4.8.83)
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-1999046)
WordPress Plugin Contact Form DB-Elementor Cross-Site Request Forgery (1.5)