PublicDate: 2007-09-04 18:17:00 UTC Candidate: CVE-2007-3997 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3997 Description: The (1) MySQL and (2) MySQLi extensions in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to bypass safe_mode and open_basedir restrictions via MySQL LOCAL INFILE operations, as demonstrated by a query with LOAD DATA LOCAL INFILE. Ubuntu-Description: Notes: kees> safe_mode/open_basedir not supported Bugs: Priority: negligible Discovered-by: Assigned-to: CVSS: upstream_php5: released (5.2.4) dapper_php5: ignored edgy_php5: ignored feisty_php5: ignored gutsy_php5: ignored devel_php5: ignored upstream_php4: released (4.4.8) dapper_php4: ignored edgy_php4: ignored feisty_php4: DNE gutsy_php4: DNE devel_php4: DNE