// For flags

CVE-2002-1405

Lynx 2.8.x - Command Line URL CRLF Injection

Severity Score

5.3
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP request that is provided on the command line, via a URL containing encoded carriage return, line feed, and other whitespace characters.

Vulnerabilidad de inyección de CRLF en Lynx 2.8.4 y anteriores permite a atacantes remotos inyectar cabeceras HTTP falsas en una petición http provista en la linea de comandos, mediante una URL conteniendo un retorno de carro codificado, salto de línea, y otros caractéres espacio en blanco.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2002-08-19 First Exploit
  • 2003-02-04 CVE Reserved
  • 2003-02-19 CVE Published
  • 2024-08-08 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Elinks
Search vendor "Elinks"
Elinks
Search vendor "Elinks" for product "Elinks"
0.2.4
Search vendor "Elinks" for product "Elinks" and version "0.2.4"
-
Affected
Elinks
Search vendor "Elinks"
Elinks
Search vendor "Elinks" for product "Elinks"
0.3.2
Search vendor "Elinks" for product "Elinks" and version "0.3.2"
-
Affected
Links
Search vendor "Links"
Links
Search vendor "Links" for product "Links"
0.96
Search vendor "Links" for product "Links" and version "0.96"
-
Affected
University Of Kansas
Search vendor "University Of Kansas"
Lynx
Search vendor "University Of Kansas" for product "Lynx"
2.8.2_rel1
Search vendor "University Of Kansas" for product "Lynx" and version "2.8.2_rel1"
-
Affected
University Of Kansas
Search vendor "University Of Kansas"
Lynx
Search vendor "University Of Kansas" for product "Lynx"
2.8.3
Search vendor "University Of Kansas" for product "Lynx" and version "2.8.3"
-
Affected
University Of Kansas
Search vendor "University Of Kansas"
Lynx
Search vendor "University Of Kansas" for product "Lynx"
2.8.3_rel1
Search vendor "University Of Kansas" for product "Lynx" and version "2.8.3_rel1"
-
Affected
University Of Kansas
Search vendor "University Of Kansas"
Lynx
Search vendor "University Of Kansas" for product "Lynx"
2.8.4
Search vendor "University Of Kansas" for product "Lynx" and version "2.8.4"
-
Affected
University Of Kansas
Search vendor "University Of Kansas"
Lynx
Search vendor "University Of Kansas" for product "Lynx"
2.8.4_rel1
Search vendor "University Of Kansas" for product "Lynx" and version "2.8.4_rel1"
-
Affected
University Of Kansas
Search vendor "University Of Kansas"
Lynx
Search vendor "University Of Kansas" for product "Lynx"
2.8.5_dev8
Search vendor "University Of Kansas" for product "Lynx" and version "2.8.5_dev8"
-
Affected