Unrated severityNVD Advisory· Published Oct 6, 2014· Updated May 6, 2026
CVE-2013-1436
CVE-2013-1436
Description
The XMonad.Hooks.DynamicLog module in xmonad-contrib before 0.11.2 allows remote attackers to execute arbitrary commands via a web page title, which activates the commands when the user clicks on the xmobar window title, as demonstrated using an action tag.
Affected products
2cpe:2.3:a:xmonad:xmonad-contrab:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:xmonad:xmonad-contrab:*:*:*:*:*:*:*:*range: <=0.11.1
- cpe:2.3:a:xmonad:xmonad-contrab:0.11:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.