RULE(RULE ID:322059)

Rule General Information
Release Date: 2019-06-27
Rule Name: DataLife Engine 9.7 Remote Code Execution Vulnerability (CVE-2013-1412)
Severity:
CVE ID:
Rule Protection Details
Description: DataLife Engine (DLE) 9.7 allows remote attackers to execute arbitrary PHP code via the catlist[] parameter to engine/preview.php, which is used in a preg_replace function call with an e modifier.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: ExploitDB:24438
SecurityFocusBID:57603
http://archives.neohapsis.com/archives/bugtraq/2013-01/0117.html
http://dleviet.com/dle/bug-fix/3281-security-patches-for-dle-97.html
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://dleviet.com/dle/bug-fix/3281-security-patches-for-dle-97.html