Spreecommerce < 0.60.2 Search Parameter RCE
Vulnerability Description
Spreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its search functionality. The application fails to properly sanitize input passed via the search[send][] parameter, which is dynamically invoked using Ruby’s send method. This allows attackers to execute arbitrary shell commands on the server without authentication.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-10019
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- joernchen
References
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/multi/http/spree_search_exec.rb
- https://www.exploit-db.com/exploits/17941
- https://web.archive.org/web/20111009192436/http://spreecommerce.com/blog/2011/10/05/remote-command-product-group/
- https://www.vulncheck.com/advisories/spreecommerce-search-parameter-rce
- https://github.com/orgs/spree
More from Spreecommerce
View All →Affected Vendor
Spreecommerce
View all reports →