CVE-2008-4690 PUBLISHED CVSS 10 CRITICAL

lynx 2.8.6dev.15 and earlier, when advanced mode is enabled and lynx is configured as a URL handler, allows remote attackers to execute arbitrary commands via a crafted lynxcgi: URL, a related issue to CVE-2005-2929. NOTE: this might only be a vulnerability in limited deployments that have defined a lynxcgi: handler.

EPSS 17.54% · 95.0th percentile

Risk Scores

CVSS v2.0
10
EPSS Score
17.54%
95.0th percentile

Affected Products

VendorProductVersions
n/an/an/a
lynxlynx0, 2.8.1, 2.8.1

Timeline

References

Open in Interactive Console →