Multiple directory traversal vulnerabilities in index.php in Zanfi CMS lite 1.2 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) flag and (2) inc parameters.Referenceshttps://www.exploit-db.com/exploits/6413https://exchange.xforce.ibmcloud.com/vulnerabilities/45027http://securityreason.com/securityalert/4290