#VU110544 Input validation error in PHP - CVE-2002-0229
Published: October 18, 2016 / Updated: June 10, 2025
Vulnerability identifier: #VU110544
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/U:Green
CVE-ID: CVE-2002-0229
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerable software:
PHP
PHP
Software vendor:
PHP Group
PHP Group
Description
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Safe Mode feature (safe_mode) in PHP 3.0 through 4.1.0 allows attackers with access to the MySQL database to bypass Safe Mode access restrictions and read arbitrary files using "LOAD DATA INFILE LOCAL" SQL statements.
Remediation
Install update from vendor's website.
External links
- http://marc.info/?l=bugtraq&m=101286577109716&w=2
- http://marc.info/?l=bugtraq&m=101304702002321&w=2
- http://marc.info/?l=ntbugtraq&m=101285016125377&w=2
- http://marc.info/?l=ntbugtraq&m=101303065423534&w=2
- http://marc.info/?l=ntbugtraq&m=101303819613337&w=2
- http://www.iss.net/security_center/static/8105.php
- http://www.securityfocus.com/bid/4026