Lucene search

K
cve[email protected]CVE-2013-1436
HistoryOct 06, 2014 - 11:55 p.m.

CVE-2013-1436

2014-10-0623:55:05
CWE-94
web.nvd.nist.gov
23
xmonad
dynamiclog
xmonad-contrib
cve-2013-1436
security vulnerability
arbitrary commands
remote code execution
web page title
xmobar window title
action tag

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.3 High

AI Score

Confidence

Low

0.067 Low

EPSS

Percentile

93.9%

The XMonad.Hooks.DynamicLog module in xmonad-contrib before 0.11.2 allows remote attackers to execute arbitrary commands via a web page title, which activates the commands when the user clicks on the xmobar window title, as demonstrated using an action tag.

Affected configurations

NVD
Node
xmonadxmonad-contrabRange0.11.1
OR
xmonadxmonad-contrabMatch0.11

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.3 High

AI Score

Confidence

Low

0.067 Low

EPSS

Percentile

93.9%