Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Lynx URI Handlers Arbitrary Command Execution Vulnerability

Lynx is prone to a vulnerability that lets attackers execute arbitrary commands. This issue occurs because the application fails to properly sanitize user-supplied input.

A remote attacker can exploit this vulnerability by tricking a victim user into following a malicious link, thus enabling the attacker to execute arbitrary commands in the context of the victim user.

UPDATE (October 27, 2008): The fix for this issue did not disable the 'lynxcgi' handler when in 'advanced' mode. This may still be an issue if Lynx is called from the command line.







 

Privacy Statement
Copyright 2009, SecurityFocus