← All CVEs

CVE-2007-3997

high · 7.5

The (1) MySQL and (2) MySQLi extensions in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to bypass safe_mode and open_basedir restrictions via MySQL LOCAL INFILE operations, as demonstrated by a query with LOAD DATA LOCAL INFILE.

7.5
CVSS
13.8%
EPSS (exploit prob.)
96th
EPSS percentile
2007-09-04
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Weaknesses

CWE-264

Affected products

VendorProductAffected versions
phpphp>= 4.0.0, < 4.4.8
phpphp>= 5.0.0, < 5.2.4

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-3997