PHP versions 5.2.4 and below suffer from a htaccess safemode and open_basedir bypass vulnerability via mail.force_extra_parameters.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/61233/php524-unsecure.txt
Source: https://packetstormsecurity.com/files/61233/php524-unsecure.txt.html

