The file names which were passed as parameters weren't filtered. Closes: #624, #625.
The methods which take said file names as parameters, now strip the '../' sequences from them, preventing access to unauthorized directories.