CVE-2011-10026
CRITICALSpreecommerce < 0.50.x - Unauthenticated Remote Code Execution via API Search Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2011-10026.
PoCs published by Metasploit, including Metasploit module exploits/multi/http/spree_searchlogic_exec.
AI-analyzed exploit summary This Metasploit module exploits an arbitrary command execution vulnerability in Spreecommerce < 0.50.0 via unvalidated input in the searchlogic API, leveraging Ruby's send method to execute commands.
Description
Spreecommerce versions prior to 0.50.x contain a remote command execution vulnerability in the API's search functionality. Improper input sanitation allows attackers to inject arbitrary shell commands via the search[instance_eval] parameter, which is dynamically invoked using Ruby’s send method. This flaw enables unauthenticated attackers to execute commands on the server.
Exploits (2)
This Metasploit module exploits an arbitrary command execution vulnerability in Spreecommerce < 0.50.0 via unvalidated input in the searchlogic API, leveraging Ruby's send method to execute commands.
This Metasploit module exploits an arbitrary command execution vulnerability in Spreecommerce API searchlogic (versions 0.50.0 and earlier) by leveraging unvalidated input via the Ruby `send` method. It sends a crafted GET request to execute a payload encoded in the URL.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H