Release date:
Updated on: 2013-02-02
Affected Systems:
Dleviet DataLife Engine 9.x
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2013-1412
DataLife Engine is a content management system written in PHP.
The vulnerability is located in/engine/preview. php. The $ _ REQUEST ['catlist'] parameter is not checked before calling preg_replace () with the e modifier. The value of $ _ REQUEST ['catlist'] is provided by the user, which allows attackers to inject and execute arbitrary PHP code, successful exploitation of this vulnerability requires the template to contain a "catlist" (or "not-catlist") Tag.
The vulnerability affects DataLife Engine 9.7 and other versions.
<* Source: Egidio Romano
Link: http://karmainsecurity.com/KIS-2013-01
Http://secunia.com/advisories/51971/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Dleviet
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://dleviet.com/dle/bug-fix/3281-security-patches-for-dle-97.html