10
CVSSv2

CVE-2008-4690

Published: 22/10/2008 Updated: 29/09/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

lynx 2.8.6dev.15 and previous versions, when advanced mode is enabled and lynx is configured as a URL handler, allows remote malicious users to execute arbitrary commands via a crafted lynxcgi: URL, a related issue to CVE-2005-2929. NOTE: this might only be a vulnerability in limited deployments that have defined a lynxcgi: handler.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lynx lynx 2.8.6

lynx lynx 2.8.5

lynx lynx 2.8.4

lynx lynx 2.8.3

lynx lynx 2.8.2

lynx lynx 2.8.1

lynx lynx

Vendor Advisories

Synopsis Important: lynx security update Type/Severity Security Advisory: Important Topic An updated lynx package that corrects two security issues is now availablefor Red Hat Enterprise Linux 21, 3, 4, and 5This update has been rated as having important security impact by the RedHat Security Response Tea ...