Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Raúl Benencia

#21082of 53,633
11.8Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2014-1882
7.5
2014-05-28
Xmonad · Xmonad-Contrib · CVE-2013-1436
**Name of the Vulnerable Software and Affected Versions** xmonad-contrib versions prior to 0.11.2 **Description** The issue allows remote attackers to execute arbitrary commands via a web page title. This can be achieved when the user clicks on the xmobar window title, as demonstrated using an action tag. The XMonad.Hooks.DynamicLog module in xmonad-contrib is affected, potentially leading to disruption of confidentiality, integrity, and availability of protected information. **Recommendations** For versions prior to 0.11.2, update to version 0.11.2 or later to resolve the issue. As a temporary workaround, consider disabling the XMonad.Hooks.DynamicLog module until a patch is available. Restrict access to the xmobar window title to minimize the risk of exploitation.
PT-2012-2411
4.3
2012-05-29
Tikiwiki · Ikiwiki · CVE-2012-0220
**Name of the Vulnerable Software and Affected Versions** ikiwiki versions prior to 3.20120516 **Description** The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML via the `author` or `authorurl` meta tags. **Recommendations** For versions prior to 3.20120516, update to version 3.20120516 or later to resolve the issue.