Description
The (1) file_exists and (2) imap_reopen functions in PHP before 5.1.5 do not check for the safe_mode and open_basedir settings, which allows local users to bypass the settings. NOTE: the error_log function is covered by CVE-2006-3011, and the imap_open function is covered by CVE-2006-1017.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Maps-Display Google Maps Perfectly with Ease Cross-Site Scripting (4.3.9)
ownCloud Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-3963)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-4408)
WordPress Plugin WPBakery Page Builder Clipboard Cross-Site Scripting (4.5.5)