Datalife Engine
Dleviet · 3 CVEs
CVE-2018-14777
MEDIUM
An issue was discovered in DataLife Engine (DLE) through 13.0. An attacker can use XSS (related to the /addnews.html an…
Aug 1, 2018
CVE-2013-7387
MEDIUM
Session fixation vulnerability in DataLife Engine (DLE) 9.7 and earlier allows remote attackers to hijack web sessions…
Jun 2, 2014
CVE-2013-1412
HIGH
DataLife Engine (DLE) 9.7 allows remote attackers to execute arbitrary PHP code via the catlist[] parameter to engine/p…
Jun 2, 2014
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2018-14777 | An issue was discovered in DataLife Engine (DLE) through 13.0. An attacker can use XSS (related to the /addnews.html and /index.php?do=addnews URIs) to send a… | MEDIUM | 0.65% | Aug 1, 2018 |
| CVE-2013-7387 | Session fixation vulnerability in DataLife Engine (DLE) 9.7 and earlier allows remote attackers to hijack web sessions via the PHPSESSID cookie. | MEDIUM | 4.96% | Jun 2, 2014 |
| CVE-2013-1412 | DataLife Engine (DLE) 9.7 allows remote attackers to execute arbitrary PHP code via the catlist[] parameter to engine/preview.php, which is used in a preg_repl… | HIGH | 40.47% | Jun 2, 2014 |
Showing 1 to 3 of 3 CVEs