peter bassill · operator
$ cve CVE-2002-1405 JSON

CVE-2002-1405 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 5% (pctl 92)

Patch early

A public exploit exists.

Description

CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP request that is provided on the command line, via a URL containing encoded carriage return, line feed, and other whitespace characters.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS5.04% — more likely to be exploited than 92% of all CVEs
On CISA KEVno
Public exploityes
Published2003-02-19
Last modified2026-06-16

Affected (3)

VendorProduct
elinkselinks
linkslinks
university of kansaslynx

Public exploits

SourceTitleDate
exploit-dbLynx 2.8.x - Command Line URL CRLF Injection2002-08-19

References

→ the Explorer  ·  watch your stack  ·  NVD