CVE-2007-3997

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
04/09/2007
Last modified:
09/04/2025

Description

The (1) MySQL and (2) MySQLi extensions in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to bypass safe_mode and open_basedir restrictions via MySQL LOCAL INFILE operations, as demonstrated by a query with LOAD DATA LOCAL INFILE.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* 4.0.0 (including) 4.4.8 (excluding)
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* 5.0.0 (including) 5.2.4 (excluding)


References to Advisories, Solutions, and Tools