CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP request that is provided on the command line, via a URL containing encoded carriage return, line feed, and other whitespace characters.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Elinks | Elinks | 0.2.4 (including) | 0.2.4 (including) |
Elinks | Elinks | 0.3.2 (including) | 0.3.2 (including) |
Links | Links | 0.96 (including) | 0.96 (including) |
Lynx | University_of_kansas | 2.8.2_rel1 (including) | 2.8.2_rel1 (including) |
Lynx | University_of_kansas | 2.8.3 (including) | 2.8.3 (including) |
Lynx | University_of_kansas | 2.8.3_rel1 (including) | 2.8.3_rel1 (including) |
Lynx | University_of_kansas | 2.8.4 (including) | 2.8.4 (including) |
Lynx | University_of_kansas | 2.8.4_rel1 (including) | 2.8.4_rel1 (including) |
Lynx | University_of_kansas | 2.8.5_dev8 (including) | 2.8.5_dev8 (including) |