CVE-2011-10019

Spreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its search functionality. The application fails to properly sanitize input passed via the search[send][] parameter, which is dynamically invoked using Ruby’s send method. This allows attackers to execute arbitrary shell commands on the server without authentication.
CVSS

No CVSS.

Configurations

No configuration.

History

14 Aug 2025, 13:11

Type Values Removed Values Added
Summary
  • (es) Las versiones de Spreecommerce anteriores a la 0.60.2 contienen una vulnerabilidad de ejecución remota de comandos en su función de búsqueda. La aplicación no depura correctamente la entrada enviada mediante el parámetro search[send][], que se invoca dinámicamente mediante el método send de Ruby. Esto permite a los atacantes ejecutar comandos de shell arbitrarios en el servidor sin autenticación.

13 Aug 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-13 21:15

Updated : 2025-08-14 13:11


NVD link : CVE-2011-10019

Mitre link : CVE-2011-10019

CVE.ORG link : CVE-2011-10019


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')