2005-02-06 05:00:00
mitre
PUBLISHED
PHP 4.0 with cURL functions allows remote attackers to bypass the open_basedir setting and read arbitrary files via a file: URL argument to the curl_init function.