CVE-2007-4889: Medium severity PHP MySQL extension vulnerability
Published Sep 14, 2007
·Updated
The MySQL extension in PHP 5.2.4 and earlier allows remote attackers to bypass safemode and openbasedir restrictions via the MySQL (1) LOADFILE, (2) INTO DUMPFILE, and (3) INTO OUTFILE functions, a different issue than CVE-2007-3997.
Affected Software
2 affected components
PHP MySQL extension
PHP PHP<=5.2.4
Event History
Sep 14, 2007
CVE Published
01:17 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-4889?
CVE-2007-4889 is classified as a high severity vulnerability due to the potential for remote exploitation.
2
How do I fix CVE-2007-4889?
To fix CVE-2007-4889, upgrade the PHP installation to version 5.2.5 or later to mitigate the vulnerability.
3
What are the implications of CVE-2007-4889?
CVE-2007-4889 allows attackers to bypass safe_mode and open_basedir restrictions, leading to unauthorized file access.
4
Which versions of PHP are affected by CVE-2007-4889?
CVE-2007-4889 affects PHP versions 5.2.4 and earlier.
5
Can CVE-2007-4889 be exploited remotely?
Yes, CVE-2007-4889 can be exploited remotely, allowing attackers to exploit vulnerabilities in the MySQL extension.