Description
PHP 5 before 5.2.3 does not enforce the open_basedir or safe_mode restriction in certain cases, which allows context-dependent attackers to determine the existence of arbitrary files by checking if the readfile function returns a string. NOTE: this issue might also involve the realpath function.
Remediation
References
Related Vulnerabilities
WordPress Plugin Translate WordPress-Google Language Translator Cross-Site Scripting (6.0.9)
TYPO3 URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2010-3669)
WordPress Plugin Duplicator-WordPress Migration Security Bypass (0.5.8)
Contao Deserialization of Untrusted Data Vulnerability (CVE-2014-1860)
Oracle Database Server CVE-2006-5341 Vulnerability (CVE-2006-5341)