CVE-2002-1405 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 5% (pctl 92)
Patch early
A public exploit exists.
Description
CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP request that is provided on the command line, via a URL containing encoded carriage return, line feed, and other whitespace characters.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
| EPSS | 5.04% — more likely to be exploited than 92% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2003-02-19 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| elinks | elinks |
| links | links |
| university of kansas | lynx |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Lynx 2.8.x - Command Line URL CRLF Injection | 2002-08-19 |
References
- ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-049.0.txt
- http://marc.info/?l=bugtraq&m=102978118411977&w=2
- http://marc.info/?l=bugtraq&m=103003793418021&w=2
- http://www.debian.org/security/2002/dsa-210
- http://www.iss.net/security_center/static/9887.php
- http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:023
- http://www.redhat.com/support/errata/RHSA-2003-029.html
- http://www.redhat.com/support/errata/RHSA-2003-030.html
- http://www.securityfocus.com/bid/5499
- http://www.trustix.net/errata/misc/2002/TSL-2002-0085-lynx-ssl.asc.txt
- ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-049.0.txt
- http://marc.info/?l=bugtraq&m=102978118411977&w=2
- http://marc.info/?l=bugtraq&m=103003793418021&w=2
- http://www.debian.org/security/2002/dsa-210
- http://www.iss.net/security_center/static/9887.php
- http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:023
- http://www.redhat.com/support/errata/RHSA-2003-029.html
- http://www.redhat.com/support/errata/RHSA-2003-030.html
- http://www.securityfocus.com/bid/5499
- http://www.trustix.net/errata/misc/2002/TSL-2002-0085-lynx-ssl.asc.txt
→ the Explorer · watch your stack · NVD