|
|||
Rule General Information |
---|
Release Date: | 2019-06-27 | |
Rule Name: | DataLife Engine 9.7 Remote Code Execution Vulnerability (CVE-2013-1412) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | DataLife Engine (DLE) 9.7 allows remote attackers to execute arbitrary PHP code via the catlist[] parameter to engine/preview.php, which is used in a preg_replace function call with an e modifier. | |
Impact: | An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software. | |
Affected OS: | Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others | |
Reference: | ExploitDB:24438 SecurityFocusBID:57603 http://archives.neohapsis.com/archives/bugtraq/2013-01/0117.html http://dleviet.com/dle/bug-fix/3281-security-patches-for-dle-97.html |
|
Solutions |
---|
The vendors have released upgrade patches to fix vulnerabilities, please visit: http://dleviet.com/dle/bug-fix/3281-security-patches-for-dle-97.html |