CVE-1999-1549

Lynx 2.x does not properly distinguish between internal and external HTML, which may allow a local attacker to read a "secure" hidden form value from a temporary file and craft a LYNXOPTIONS: URL that causes Lynx to modify the user's configuration file and execute commands.
References
Link Resource
http://marc.info/?l=bugtraq&m=94286509804526&w=2 Exploit Mailing List
http://www.securityfocus.com/bid/804 Broken Link Exploit Third Party Advisory VDB Entry Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:lynx_project:lynx:2.7:*:*:*:*:*:*:*
cpe:2.3:a:lynx_project:lynx:2.8:*:*:*:*:*:*:*

History

08 Feb 2024, 20:46

Type Values Removed Values Added
CWE NVD-CWE-Other CWE-346
References () http://marc.info/?l=bugtraq&m=94286509804526&w=2 - () http://marc.info/?l=bugtraq&m=94286509804526&w=2 - Exploit, Mailing List
References () http://www.securityfocus.com/bid/804 - Exploit, Vendor Advisory () http://www.securityfocus.com/bid/804 - Broken Link, Exploit, Third Party Advisory, VDB Entry, Vendor Advisory
First Time Lynx Project
Lynx Project lynx
CVSS v2 : 5.0
v3 : unknown
v2 : 5.0
v3 : 7.8
CPE cpe:2.3:a:university_of_kansas:lynx:2.7:*:*:*:*:*:*:*
cpe:2.3:a:university_of_kansas:lynx:2.8:*:*:*:*:*:*:*
cpe:2.3:a:lynx_project:lynx:2.7:*:*:*:*:*:*:*
cpe:2.3:a:lynx_project:lynx:2.8:*:*:*:*:*:*:*

Information

Published : 1999-11-16 05:00

Updated : 2024-02-08 20:46


NVD link : CVE-1999-1549

Mitre link : CVE-1999-1549

CVE.ORG link : CVE-1999-1549


JSON object : View

Products Affected

lynx_project

  • lynx
CWE
CWE-346

Origin Validation Error