PT-2002-1300 · Php+1 · Php+1

Published

2002-05-03

·

Updated

2016-10-18

·

CVE-2002-0229

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHP versions 3.0 through 4.1.0
Description The issue allows attackers with access to the MySQL database to bypass access restrictions and read arbitrary files using SQL statements, specifically "LOAD DATA INFILE LOCAL".
Recommendations For PHP versions 3.0 through 4.1.0, consider restricting access to the MySQL database to minimize the risk of exploitation. As a temporary workaround, restrict the use of "LOAD DATA INFILE LOCAL" SQL statements until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0229

Affected Products

Mysql Server
Php