CVE-2007-4889

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/09/2007
Last modified:
09/04/2025

Description

The MySQL extension in PHP 5.2.4 and earlier allows remote attackers to bypass safe_mode and open_basedir restrictions via the MySQL (1) LOAD_FILE, (2) INTO DUMPFILE, and (3) INTO OUTFILE functions, a different issue than CVE-2007-3997.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:php:mysql_extension:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* 5.2.4 (including)