← Vulnerability feed

Vulnerability record · CVE-2008-6591 · published 3 April 2009

CVE-2008-6591: Lightneasy code injection vulnerability

Lightneasy · Lightneasy

LightNEasy "no database" (aka flat) version 1.2.2, and possibly SQLite version 1.2.2, allows remote attackers to create arbitrary files via the page parameter to (1) index.php and (2) LightNEasy.php.

5.0 CVSS 2.0 Medium EPSS 1.3% · top 31.4% CWE-94 · Code injection
5.0CVSS 2.0 base score
1.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

LightNEasy "no database" (aka flat) version 1.2.2, and possibly SQLite version 1.2.2, allows remote attackers to create arbitrary files via the page parameter to (1) index.php and (2) LightNEasy.php.

AV:N/AC:L/Au:N/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-6591 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2010-3484Lightneasy sql injection vulnerabilitySQL injection vulnerability in common.php in LightNEasy 3.2.1 allows remote attackers to execute arbitrary SQL commands via the handle parameter to L…EPSS 1.3%7.5CVE-2010-3485Lightneasy sql injection vulnerabilitySQL injection vulnerability in common.php in LightNEasy 3.2.1 allows remote attackers to execute arbitrary SQL commands via the userhandle cookie to …EPSS 1.3%7.5CVE-2008-6592Lightneasy path traversal vulnerabilitythumbsup.php in Thumbs-Up 1.12, as used in LightNEasy "no database" (aka flat) and SQLite 1.2.2 and earlier, allows remote attackers to copy, rename,…EPSS 2.9%7.5CVE-2008-6593Lightneasy sql injection vulnerabilitySQL injection vulnerability in LightNEasy/lightneasy.php in LightNEasy SQLite 1.2.2 and earlier allows remote attackers to inject arbitrary PHP code …EPSS 3.5%6.8CVE-2010-4752Lightneasy sql injection vulnerabilitySQL injection vulnerability in LightNEasy.php in LightNEasy 3.2.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQ…EPSS 0.90%6.0CVE-2010-4751Lightneasy sql injection vulnerabilitySQL injection vulnerability in LightNEasy.php in LightNEasy 3.2.1, when magic_quotes_gpc is disabled, allows remote authenticated users to execute ar…EPSS 0.82%5.0CVE-2008-6590Lightneasy path traversal vulnerabilityMultiple directory traversal vulnerabilities in LightNEasy "no database" (aka flat) version 1.2.2, and possibly SQLite version 1.2.2, allow remote at…EPSS 3.4%5.0CVE-2008-6537Lightneasy information exposure vulnerabilityLightNEasy/lightneasy.php in LightNEasy No database version 1.2 allows remote attackers to obtain the hash of the administrator password via the setu…EPSS 6.3%

Source: NIST National Vulnerability Database (record CVE-2008-6591), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.