CVE-2013-4407

Severity

68%

Complexity

86%

Confidentiality

106%

HTTP::Body::Multipart in the HTTP-Body 1.08, 1.17, and earlier module for Perl uses the part of the uploaded file's name after the first "." character as the suffix of a temporary file, which makes it easier for remote attackers to conduct attacks by leveraging subsequent behavior that may assume the suffix is well-formed.

HTTP::Body::Multipart in the HTTP-Body 1.08, 1.17, and earlier module for Perl uses the part of the uploaded file's name after the first "." character as the suffix of a temporary file, which makes it easier for remote attackers to conduct attacks by leveraging subsequent behavior that may assume the suffix is well-formed.

CVSS 2.0 Base Score 6.8. CVSS Attack Vector: network. CVSS Attack Complexity: medium. CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P).

Overview

Type

HTTP-Body Project HTTP-Body

First reported 11 years ago

2013-11-23 18:55:00

Last updated 10 years ago

2014-04-01 06:23:00

Affected Software

HTTP-Body Project HTTP-Body 0.01

0.01

HTTP-Body Project HTTP-Body 0.2

0.2

HTTP-Body Project HTTP-Body 0.03

0.03

HTTP-Body Project HTTP-Body 0.4

0.4

HTTP-Body Project HTTP-Body 0.5

0.5

HTTP-Body Project HTTP-Body 0.6

0.6

HTTP-Body Project HTTP-Body 0.7

0.7

HTTP-Body Project HTTP-Body 0.8

0.8

HTTP-Body Project HTTP-Body 0.9

0.9

HTTP-Body Project HTTP-Body 1.00

1.00

HTTP-Body Project HTTP-Body 1.01

1.01

HTTP-Body Project HTTP-Body 1.02

1.02

HTTP-Body Project HTTP-Body 1.03

1.03

HTTP-Body Project HTTP-Body 1.04

1.04

HTTP-Body Project HTTP-Body 1.05

1.05

HTTP-Body Project HTTP-Body 1.06

1.06

HTTP-Body Project HTTP-Body 1.07

1.07

HTTP-Body Project HTTP-Body 1.08

1.08

HTTP-Body Project HTTP-Body 1.09

1.09

HTTP-Body Project HTTP-Body 1.10

1.10

HTTP-Body Project HTTP-Body 1.11

1.11

HTTP-Body Project HTTP-Body 1.12

1.12

HTTP-Body Project HTTP-Body 1.14

1.14

HTTP-Body Project HTTP-Body 1.15

1.15

HTTP-Body Project HTTP-Body 1.16

1.16

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.