Vendorsdlevietdatalife_engineall versions
Vulnerabilities

dleviet DataLife Engine

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2013-1412
DataLife Engine (DLE) 9.7 allows remote attackers to execute arbitrary PHP code via the catlist[] parameter to engine/preview.php, which is used in a preg_replace function call with an e modifier.
Published 2014-06-02 · Modified
7.52 PoCEPSS 0.405
CVE-2013-7387
Session fixation vulnerability in DataLife Engine (DLE) 9.7 and earlier allows remote attackers to hijack web sessions via the PHPSESSID cookie.
Published 2014-06-02 · Modified
6.82 PoCEPSS 0.050
CVE-2018-14777
An issue was discovered in DataLife Engine (DLE) through 13.0. An attacker can use XSS (related to the /addnews.html and /index.php?do=addnews URIs) to send a malicious script to unsuspecting Admins or users.
Published 2018-08-01 · Modified
5.4EPSS 0.007