CVE-2013-1436

EPSS 7.1%

code injection in xmonad-contrib

發布日:2025/11/14修改日:2026/4/28
也稱為:DEBIAN-CVE-2013-1436HSEC-2023-0003

描述

The XMonad.Hooks.DynamicLog module in xmonad-contrib before 0.11.2 allows remote attackers to execute arbitrary commands via a web page title, which activates the commands when the user clicks on the xmobar window title, as demonstrated using an action tag.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 2.0AV:N/AC:L/Au:N/C:P/I:P/A:P

參考連結(4)