CVE-2013-1412

high
Published 2014-06-02 · Modified 2026-05-06
CVSS v3
CVSS v2
7.5
VIR risk
7.5

Description

DataLife Engine (DLE) 9.7 allows remote attackers to execute arbitrary PHP code via the catlist[] parameter to engine/preview.php, which is used in a preg_replace function call with an e modifier.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://dleviet.com/dle/bug-fix/3281-security-patches-for-dle-97.html

Application impact

VendorProductVersionsFixed
dlevietdatalife_engine9.7

References

CWEs

CWE-94

Verify integrity in audit chain (admin only). AS-IS.