emlog through 6.0.0beta has an arbitrary file deletion vulnerability via an admin/data.php?action=dell_all_bak request with directory traversal sequences in the bak[] parameter.
| Software | From | Fixed in |
|---|---|---|
| emlog / emlog | 6.0.0-beta | 6.0.0-beta.x |
| emlog / emlog | - | 5.3.1.x |