HTTP::Body::Multipart in the HTTP-Body module for Perl (1.07 through 1.22, before 1.23) uses the part of the uploaded file's name after the first "." character as the suffix of a temporary file, which makes it easier for remote attackers to conduct attacks by leveraging subsequent behavior that may assume the suffix is well-formed.
References
Configurations
Configuration 1 (hide)
|
History
01 May 2024, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
12 Apr 2024, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| Summary | HTTP::Body::Multipart in the HTTP-Body module for Perl (1.07 through 1.22, before 1.23) uses the part of the uploaded file's name after the first "." character as the suffix of a temporary file, which makes it easier for remote attackers to conduct attacks by leveraging subsequent behavior that may assume the suffix is well-formed. |
01 Apr 2024, 00:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Information
Published : 2013-11-23 18:55
Updated : 2024-05-01 18:15
NVD link : CVE-2013-4407
Mitre link : CVE-2013-4407
JSON object : View
Products Affected
http-body_project
- http-body
CWE
