|
Lynx URI Handlers Arbitrary Command Execution Vulnerability
Lynx is prone to a vulnerability that lets attackers execute arbitrary commands. This issue occurs because the application fails to properly sanitize user-supplied input. A remote attacker can exploit this vulnerability by tricking a victim user into following a malicious link, thus enabling the attacker to execute arbitrary commands in the context of the victim user. UPDATE (October 27, 2008): The fix for this issue did not disable the 'lynxcgi' handler when in 'advanced' mode. This may still be an issue if Lynx is called from the command line. |
|
|
Privacy Statement |