Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-1097

Опубликовано: 24 мар. 2010
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

include/userlogin.class.php in DeDeCMS 5.5 GBK, when session.auto_start is enabled, allows remote attackers to bypass authentication and gain administrative access via a value of 1 for the _SESSION[dede_admin_id] parameter, as demonstrated by a request to uploads/include/dialog/select_soft_post.php.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:dedecms:dedecms:5.5:*:*:*:*:*:*:*

EPSS

Процентиль: 32%
0.00123
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-287

Связанные уязвимости

github
почти 4 года назад

include/userlogin.class.php in DeDeCMS 5.5 GBK, when session.auto_start is enabled, allows remote attackers to bypass authentication and gain administrative access via a value of 1 for the _SESSION[dede_admin_id] parameter, as demonstrated by a request to uploads/include/dialog/select_soft_post.php.

EPSS

Процентиль: 32%
0.00123
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-287