CVE-2010-1097: Medium severity DedeCMS Dedecms vulnerability
include/userlogin.class.php in DeDeCMS 5.5 GBK, when session.autostart is enabled, allows remote attackers to bypass authentication and gain administrative access via a value of 1 for the SESSION[dedeadminid] parameter, as demonstrated by a request to uploads/include/dialog/selectsoftpost.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1097?
CVE-2010-1097 is classified as a critical severity vulnerability due to its potential for unauthorized administrative access.
How do I fix CVE-2010-1097?
To fix CVE-2010-1097, disable session.auto_start in your PHP configuration and ensure secure handling of session variables.
Who is affected by CVE-2010-1097?
CVE-2010-1097 affects users of DeDeCMS version 5.5 GBK when session.auto_start is enabled.
Can CVE-2010-1097 lead to data breaches?
Yes, CVE-2010-1097 can lead to data breaches by allowing attackers to gain unauthorized administrative access.
What are the consequences of exploiting CVE-2010-1097?
Exploiting CVE-2010-1097 can result in complete control over the web application by malicious actors.