CVE-2011-10019
🔴 Łataj teraz
Wykonanie zdalnego kodu w Spreecommerce umożliwia atakującym uruchamianie poleceń na serwerze.
CVSS
9.8
EPSS
5.8%
Exploit
poc
Vendor
spreecommerce
Opis źródłowy (NVD)
Spreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its search functionality. The application fails to properly sanitize input passed via the search[send][] parameter, which is dynamically invoked using Ruby’s send method. This allows attackers to execute arbitrary shell commands on the server without authentication.
exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 5.8% |
| Opublikowano (NVD) | 2025-08-13 21:15:29 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 16:16:41 UTC |
Referencje
- https://github.com/orgs/spree ([email protected]) [Product]
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/multi/http/spree_search_exec.rb ([email protected]) [Exploit, Third Party Advisory]
- https://web.archive.org/web/20111009192436/http://spreecommerce.com/blog/2011/10/05/remote-command-product-group/ ([email protected]) [Release Notes]
- https://www.exploit-db.com/exploits/17941 ([email protected]) [Exploit, VDB Entry]
- https://www.vulncheck.com/advisories/spreecommerce-search-parameter-rce ([email protected]) [Third Party Advisory]