Логотип exploitDog
bind:CVE-2011-10026
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2011-10026

Количество 2

Количество 2

nvd логотип

CVE-2011-10026

6 месяцев назад

Spreecommerce versions prior to 0.50.x contain a remote command execution vulnerability in the API's search functionality. Improper input sanitation allows attackers to inject arbitrary shell commands via the search[instance_eval] parameter, which is dynamically invoked using Ruby’s send method. This flaw enables unauthenticated attackers to execute commands on the server.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-x485-rhg3-cqr4

6 месяцев назад

Spree Commerce is vulnerable to RCE through Search API

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2011-10026

Spreecommerce versions prior to 0.50.x contain a remote command execution vulnerability in the API's search functionality. Improper input sanitation allows attackers to inject arbitrary shell commands via the search[instance_eval] parameter, which is dynamically invoked using Ruby’s send method. This flaw enables unauthenticated attackers to execute commands on the server.

CVSS3: 9.8
65%
Средний
6 месяцев назад
github логотип
GHSA-x485-rhg3-cqr4

Spree Commerce is vulnerable to RCE through Search API

65%
Средний
6 месяцев назад

Уязвимостей на страницу