VDB
CVE-2005-2929
CVE-2005-2929
PUBLISHED
CVSS 7.5 HIGH
Lynx 2.8.5, and other versions before 2.8.6dev.15, allows remote attackers to execute arbitrary commands via (1) lynxcgi:, (2) lynxexec, and (3) lynxprog links, which are not properly restricted in the default configuration in some environments.
EPSS 4.92% · 91.9th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
4.92%
91.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | * |
| university_of_kansas | lynx | 2.8.5, 2.8.6, 2.8.6_dev13 |
Timeline
- Nov 18, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 13, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 4, 2023 EPSS Score
- May 27, 2023 EPSS Score
- Jul 19, 2023 EPSS Score
- Sep 10, 2023 EPSS Score
References
- 17556 third-party-advisory
- 18376 third-party-advisory
- 17757 third-party-advisory
- FLSA:152832 vendor-advisory
- MDKSA-2005:211 vendor-advisory
- 17372 third-party-advisory
- SCOSA-2005.55 vendor-advisory
- 17666 third-party-advisory
- SCOSA-2006.7 vendor-advisory
- http://secunia.com/advisories/17512 advisory
- http://secunia.com/advisories/17546 advisory
- http://securityreason.com/securityalert/173 technical
- http://securitytracker.com/id?1015195 technical
- http://support.avaya.com/elmodocs2/security/ASA-2006-035.htm technical
- http://www.gentoo.org/security/en/glsa/glsa-200511-09.xml technical
- http://www.redhat.com/support/errata/RHSA-2005-839.html technical
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23119 technical
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9712 technical
- http://secunia.com/advisories/17576 advisory
- http://secunia.com/advisories/18051 advisory
…and 6 more