Description
The (1) MySQL and (2) MySQLi extensions in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to bypass safe_mode and open_basedir restrictions via MySQL LOCAL INFILE operations, as demonstrated by a query with LOAD DATA LOCAL INFILE.
Remediation
References
Related Vulnerabilities
WordPress Plugin ImageBoss-Images Up To 60% Smaller & CDN Cross-Site Scripting (3.0.4)
Envoy mishandles dropped and truncated datagrams Issue (CVE-2020-35471)
WordPress Plugin WP Limit Login Attempts SQL Injection (2.0.0)
WordPress Plugin Timetable and Event Schedule by MotoPress Information Disclosure (2.3.19)