CVE Vulnerabilities

CVE-2002-0229

Published: May 16, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Safe Mode feature (safe_mode) in PHP 3.0 through 4.1.0 allows attackers with access to the MySQL database to bypass Safe Mode access restrictions and read arbitrary files using LOAD DATA INFILE LOCAL SQL statements.

Affected Software

NameVendorStart VersionEnd Version
PhpPhp3.0 (including)3.0 (including)
PhpPhp3.0.1 (including)3.0.1 (including)
PhpPhp3.0.2 (including)3.0.2 (including)
PhpPhp3.0.3 (including)3.0.3 (including)
PhpPhp3.0.4 (including)3.0.4 (including)
PhpPhp3.0.5 (including)3.0.5 (including)
PhpPhp3.0.6 (including)3.0.6 (including)
PhpPhp3.0.7 (including)3.0.7 (including)
PhpPhp3.0.8 (including)3.0.8 (including)
PhpPhp3.0.9 (including)3.0.9 (including)
PhpPhp3.0.10 (including)3.0.10 (including)
PhpPhp3.0.11 (including)3.0.11 (including)
PhpPhp3.0.12 (including)3.0.12 (including)
PhpPhp3.0.13 (including)3.0.13 (including)
PhpPhp3.0.16 (including)3.0.16 (including)
PhpPhp4.0 (including)4.0 (including)
PhpPhp4.0.1 (including)4.0.1 (including)
PhpPhp4.0.1-patch2 (including)4.0.1-patch2 (including)
PhpPhp4.0.3 (including)4.0.3 (including)
PhpPhp4.0.4 (including)4.0.4 (including)
PhpPhp4.0.5 (including)4.0.5 (including)
PhpPhp4.0.6 (including)4.0.6 (including)
PhpPhp4.1.0 (including)4.1.0 (including)
PhpPhp4.1.2 (including)4.1.2 (including)

References