Description
The (1) file_exists and (2) imap_reopen functions in PHP before 5.1.5 do not check for the safe_mode and open_basedir settings, which allows local users to bypass the settings. NOTE: the error_log function is covered by CVE-2006-3011, and the imap_open function is covered by CVE-2006-1017.
Remediation
References
Related Vulnerabilities
Undertow CVE-2022-4492 Vulnerability (CVE-2022-4492)
WordPress Plugin WordPress Gallery Cross-Site Scripting (1.0)
WordPress Plugin Yoast SEO Cross-Site Scripting (2.0.1)
WordPress Plugin Caldera Forms-More Than Contact Forms Arbitrary File Disclosure (1.8.1)
WordPress Plugin Uncanny Toolkit for LearnDash Cross-Site Request Forgery (3.6.3)