PHP Permissions Privileges and Access Controls Vulnerability - CVE-2007-3997
The (1) MySQL and (2) MySQLi extensions in PHP 4 before 4.4.8 and PHP 5 before 5.2.4 allow remote attackers to bypass safe_mode and open_basedir restrictions via MySQL LOCAL INFILE operations as demonstrated by a query with LOAD DATA LOCAL INFILE.