Title: DataLife Engine 9.7 (preview. php) PHP Code Injection Vulnerability software connection: http://dleviet.com/ Affected Version: 9.7 defect overview is located in/engine/preview. php script: 246. $ c_list = implode (',', $ _ REQUEST ['catlist']); 247. 248. if (strpos ($ tpl-> copy_template, "[catlist = ")! = False) {249. $ tpl-> copy_template = preg_replace ("#\\ [catlist = (. + ?) \] (. *?) \ [/Catlist \] # ies "," check_category ('\ 1',' \ 2', '{$ c_list }')", $ tpl-> copy_template); 250 .} 251. www.2cto.com 252. if (strpos ($ tpl-> copy_template, "[not-catlist = ")! = False) {253. $ tpl-> copy_template = preg_replace ("# \ [not-catlist = (. + ?) \] (. *?) \ [/Not-catlist \] # ies "," check_category ('\ 1',' \ 2 ',' {$ c_list} ', false )", $ tpl-> copy_template); 254 .} user supplied input passed through the $ _ REQUEST ['catlist'] parameter is not properly sanitized before being used in a preg_replace () call with the e modifier at lines 249 and 253. this can be exploited to inject and execute arbitrary PHP code. successful exploitation of this vulnerability requires a template which contains a "catlist" (or a "not-catlist") tag. solution: patch: http://dleviet.com/ Dle/bug-fix/3281-security-patches-for-dle-97.html