SQL injection vulnerability in LightNEasy/lightneasy.php in LightNEasy SQLite 1.2.2 and earlier allows remote attackers to inject arbitrary PHP code into comments.dat via the dlid parameter to index.php.Referenceshttp://www.securityfocus.com/bid/28801http://www.securityfocus.com/archive/1/491064/100/0/threadedhttp://www.osvdb.org/44675http://secunia.com/advisories/29833https://www.exploit-db.com/exploits/5452https://exchange.xforce.ibmcloud.com/vulnerabilities/42009