Unrated severityNVD Advisory· Published Mar 24, 2010· Updated Apr 29, 2026
CVE-2010-1097
CVE-2010-1097
Description
include/userlogin.class.php in DeDeCMS 5.5 GBK, when session.auto_start is enabled, allows remote attackers to bypass authentication and gain administrative access via a value of 1 for the _SESSION[dede_admin_id] parameter, as demonstrated by a request to uploads/include/dialog/select_soft_post.php.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- bbs.wolvez.org/topic/125/nvdExploit
- www.securityfocus.com/bid/38469nvdExploit
- secunia.com/advisories/38790nvdVendor Advisory
- osvdb.org/62622nvd
News mentions
0No linked articles in our index yet.