emlog through 6.0.0beta allows remote authenticated users to delete arbitrary files via admin/template.php?action=del&tpl=../ directory traversal.
emlog through 6.0.0beta has an arbitrary file deletion vulnerability via an admin/data.php?action=dellallbak request with directory traversal sequences in the bak[] parameter.