Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Raúl Benencia

#21011de 53,635
11.8CVSS total
Vulnerabilidades · 2
Média
1
Alta
1
PT-2014-1882
7.5
2014-05-28
Xmonad · Xmonad-Contrib · CVE-2013-1436
**Name of the Vulnerable Software and Affected Versions** xmonad-contrib versions prior to 0.11.2 **Description** The issue allows remote attackers to execute arbitrary commands via a web page title. This can be achieved when the user clicks on the xmobar window title, as demonstrated using an action tag. The XMonad.Hooks.DynamicLog module in xmonad-contrib is affected, potentially leading to disruption of confidentiality, integrity, and availability of protected information. **Recommendations** For versions prior to 0.11.2, update to version 0.11.2 or later to resolve the issue. As a temporary workaround, consider disabling the XMonad.Hooks.DynamicLog module until a patch is available. Restrict access to the xmobar window title to minimize the risk of exploitation.
PT-2012-2411
4.3
2012-05-29
Tikiwiki · Ikiwiki · CVE-2012-0220
**Name of the Vulnerable Software and Affected Versions** ikiwiki versions prior to 3.20120516 **Description** The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML via the `author` or `authorurl` meta tags. **Recommendations** For versions prior to 3.20120516, update to version 3.20120516 or later to resolve the issue.