CVE-2008-6591

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
03/04/2009
Last modified:
09/04/2025

Description

LightNEasy "no database" (aka flat) version 1.2.2, and possibly SQLite version 1.2.2, allows remote attackers to create arbitrary files via the page parameter to (1) index.php and (2) LightNEasy.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lightneasy:lightneasy:1.2.2:*:no_database:*:*:*:*:*
cpe:2.3:a:lightneasy:lightneasy:1.2.2:*:sqlite:*:*:*:*:*