vendor:
DataLife Engine
by:
EgiX, juan vazquez
N/A
CVSS
N/A
Code Injection
94
CWE
Product Name: DataLife Engine
Affected Version From: DataLife Engine 9.7
Affected Version To: DataLife Engine 9.7
Patch Exists: YES
Related CWE: CVE-2013-1412
CPE: a:datalife_engine:datalife_engine
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: PHP
2013
DataLife Engine preview.php PHP Code Injection
This module exploits a PHP code injection vulnerability DataLife Engine 9.7. The vulnerability exists in preview.php, due to an insecure usage of preg_replace() with the e modifier, which allows to inject arbitrary php code, when the template in use contains a [catlist] or [not-catlist] tag.
Mitigation:
Update to DataLife Engine 9.7 or later version