Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:4603
HistoryJul 19, 2017 - 9:42 p.m.

Changeable Host Values

2017-07-1921:42:15
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

EPSS

0.001

Percentile

40.1%

Lynx has changeable host values. It doesn’t parse the authority component of the URL when the url ends with ?. Using this flaw, attackers can trick the application into connecting to a different host value.