CVE-2013-7387

DataLife Engine <9.7 - Info Disclosure

Title source: llm

Description

Session fixation vulnerability in DataLife Engine (DLE) 9.7 and earlier allows remote attackers to hijack web sessions via the PHPSESSID cookie.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotephp
https://www.exploit-db.com/exploits/24444
exploitdb WRITEUP VERIFIED
by EgiX · textwebappsphp
https://www.exploit-db.com/exploits/24438

Scores

EPSS 0.0204
EPSS Percentile 83.9%

Details

Status published
Products (1)
dleviet/datalife_engine < 9.7
Published Jun 02, 2014
Tracked Since Feb 18, 2026