Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2008-4690

lynx 2.8.6dev.15 and earlier, when advanced mode is enabled and lynx is configured as a URL handler, allows remote attackers to execute arbitrary commands via a crafted lynxcgi: URL, a related issue to CVE-2005-2929. NOTE: this might only be a vulnerability in limited deployments that have defined a lynxcgi: handler.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.189
EPSS Ranking 95.0%
CVSS Severity
CVSS v2 Score 10.0
References
Products affected by CVE-2008-4690
  • Lynx » Lynx » Version: Any
    cpe:2.3:a:lynx:lynx:*
  • Lynx » Lynx » Version: 2.8.1
    cpe:2.3:a:lynx:lynx:2.8.1
  • Lynx » Lynx » Version: 2.8.2
    cpe:2.3:a:lynx:lynx:2.8.2
  • Lynx » Lynx » Version: 2.8.3
    cpe:2.3:a:lynx:lynx:2.8.3
  • Lynx » Lynx » Version: 2.8.4
    cpe:2.3:a:lynx:lynx:2.8.4
  • Lynx » Lynx » Version: 2.8.5
    cpe:2.3:a:lynx:lynx:2.8.5
  • Lynx » Lynx » Version: 2.8.6
    cpe:2.3:a:lynx:lynx:2.8.6


Contact Us

Shodan ® - All rights reserved