Description
PHP 4.0 with cURL functions allows remote attackers to bypass the open_basedir setting and read arbitrary files via a file: URL argument to the curl_init function.
Remediation
References
Related Vulnerabilities
WordPress Plugin DVS Custom Notification Multiple Cross-Site Request Forgery Vulnerabilities (1.0.1)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-7833)
Joomla! Core 1.6.x Security Bypass (1.6.0 - 1.6.6)
WordPress Plugin HDW Player (Video Player & Video Gallery) SQL Injection (2.4.2)