PHP Other Vulnerability - CVE-2007-1835
PHP 4 before 4.4.5 and PHP 5 before 5.2.1 when using an empty session save path (session.save_path) uses the TMPDIR default after checking the restrictions which allows local users to bypass open_basedir restrictions.
