Lynx 2.x does not properly distinguish between internal and external HTML, which may allow a local attacker to read a secure hidden form value from a temporary file and craft a LYNXOPTIONS: URL that causes Lynx to modify the users configuration file and execute commands.
The product does not properly verify that the source of data or communication is valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Lynx | Lynx_project | 2.7 (including) | 2.7 (including) |
Lynx | Lynx_project | 2.8 (including) | 2.8 (including) |