CVE-2013-1436
EPSS 7.1%code injection in xmonad-contrib
發布日:2025/11/14修改日:2026/4/28
也稱為:DEBIAN-CVE-2013-1436HSEC-2023-0003
描述
The XMonad.Hooks.DynamicLog module in xmonad-contrib before 0.11.2 allows remote attackers to execute arbitrary commands via a web page title, which activates the commands when the user clicks on the xmobar window title, as demonstrated using an action tag.
受影響套件(2)
- Debian/xmonad-contribfrom 0, < 0.11.2-1
- Hackage/xmonad-contrib>= 0.5, < 0.11.2
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 2.0 | — | AV:N/AC:L/Au:N/C:P/I:P/A:P |