LionWiki before 3.2.12 allows an unauthenticated user to read files as the web server user via crafted string in the index.php f1 variable, aka Local File Inclusion. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Lionwiki | Lionwiki | * | 3.2.12 (excluding) |