Multiple directory traversal vulnerabilities in LightNEasy "no database" (aka flat) version 1.2.2, and possibly SQLite version 1.2.2, allow remote attackers to read arbitrary files via a .. (dot dot) in the page parameter to (1) index.php and (2) LightNEasy.php.
| Product | Vendor | Version |
|---|---|---|
| n/a | n/a | < d601fd24e6964967f115f036a840f4f28488f63f |