Lucene search

K
cve[email protected]CVE-2013-1412
HistoryJun 02, 2014 - 3:55 p.m.

CVE-2013-1412

2014-06-0215:55:09
CWE-94
web.nvd.nist.gov
108
datalife engine
dle 9.7
remote execution
arbitrary php code
cve-2013-1412
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.5 High

AI Score

Confidence

Low

0.961 High

EPSS

Percentile

99.5%

DataLife Engine (DLE) 9.7 allows remote attackers to execute arbitrary PHP code via the catlist[] parameter to engine/preview.php, which is used in a preg_replace function call with an e modifier.

Affected configurations

NVD
Node
dlevietdatalife_engineMatch9.7

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.5 High

AI Score

Confidence

Low

0.961 High

EPSS

Percentile

99.5%