Launchpad.net

CVE 2004-1392

PHP 4.0 with cURL functions allows remote attackers to bypass the open_basedir setting and read arbitrary files via a file: URL argument to the curl_init function.

See the CVE page on Mitre.org for more details.