CVE-2013-1412
02.06.2014, 15:55
DataLife Engine (DLE) 9.7 allows remote attackers to execute arbitrary PHP code via the catlist[] parameter to engine/preview.php, which is used in a preg_replace function call with an e modifier.
Vendor | Product | Version |
---|---|---|
dleviet | datalife_engine | 9.7 |
𝑥
= Vulnerable software versions
References