PHP versions 5.3 and below suffer from a mysqli_real_escape_string() related full path disclosure vulnerability.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/81699/major_rls59.txt
Source: https://packetstormsecurity.com/files/81699/PHP-5.3-mysqli_real_escape_String-Disclosure.html

