Security Advisory
CVE-2008-6591
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
LightNEasy "no database" (aka flat) version 1.2.2, and possibly SQLite version 1.2.2, allows remote attackers to create arbitrary files via the page parameter to (1) index.php and (2) LightNEasy.php.