PT-2002-1300 · Php+1 · Php+1

Publicado

2002-05-03

·

Atualizado

2016-10-18

·

CVE-2002-0229

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHP versions 3.0 through 4.1.0
Description The issue allows attackers with access to the MySQL database to bypass access restrictions and read arbitrary files using SQL statements, specifically "LOAD DATA INFILE LOCAL".
Recommendations For PHP versions 3.0 through 4.1.0, consider restricting access to the MySQL database to minimize the risk of exploitation. As a temporary workaround, restrict the use of "LOAD DATA INFILE LOCAL" SQL statements until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0229

Produtos afetados

Mysql Server
Php