6.8
CVSSv2

CVE-2013-7387

Published: 02/06/2014 Updated: 03/06/2014
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 690
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Session fixation vulnerability in DataLife Engine (DLE) 9.7 and previous versions allows remote malicious users to hijack web sessions via the PHPSESSID cookie.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dleviet datalife engine

Exploits

## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # web site for more information on licensing and terms of use # metasploitcom/ ## require 'msf/core' class Metasploit3 < Msf::Exploit::Remote Rank = ExcellentRanking include Msf::Exploit ...
------------------------------------------------------------------ DataLife Engine 97 (previewphp) PHP Code Injection Vulnerability ------------------------------------------------------------------ [-] Software Link: dlevietcom/ [-] Affected Version: 97 only [-] Vulnerability Description: The vulnerable code is located in the / ...