CVE-2010-1097
DeDeCMS 5.5 GBK - Auth Bypass
Title source: llmDescription
include/userlogin.class.php in DeDeCMS 5.5 GBK, when session.auto_start is enabled, allows remote attackers to bypass authentication and gain administrative access via a value of 1 for the _SESSION[dede_admin_id] parameter, as demonstrated by a request to uploads/include/dialog/select_soft_post.php.
Scores
EPSS
0.0012
EPSS Percentile
31.3%
Classification
CWE
CWE-287
Status
draft
Affected Products (1)
dedecms/dedecms
Timeline
Published
Mar 24, 2010
Tracked Since
Feb 18, 2026