CVE-2002-1405

CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP request that is provided on the command line, via a URL containing encoded carriage return, line feed, and other whitespace characters.

Scoring

CVSS base score
0.52
EPSS probability
13.12%
Published
2004-09-01
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs