VYPR
Unrated severityNVD Advisory· Published Nov 23, 2013· Updated Apr 29, 2026

CVE-2013-4407

CVE-2013-4407

Description

HTTP::Body::Multipart in the HTTP-Body module for Perl (1.07 through 1.22, before 1.23) uses the part of the uploaded file's name after the first "." character as the suffix of a temporary file, which makes it easier for remote attackers to conduct attacks by leveraging subsequent behavior that may assume the suffix is well-formed.

Affected products

26
  • cpe:2.3:a:http-body_project:http-body:*:*:*:*:*:*:*:*+ 25 more
    • cpe:2.3:a:http-body_project:http-body:*:*:*:*:*:*:*:*range: <=1.17
    • cpe:2.3:a:http-body_project:http-body:0.01:*:*:*:*:*:*:*
    • cpe:2.3:a:http-body_project:http-body:0.03:*:*:*:*:*:*:*
    • cpe:2.3:a:http-body_project:http-body:0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:http-body_project:http-body:0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:http-body_project:http-body:0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:http-body_project:http-body:0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:http-body_project:http-body:0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:http-body_project:http-body:0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:http-body_project:http-body:0.9:*:*:*:*:*:*:*
    • cpe:2.3:a:http-body_project:http-body:1.00:*:*:*:*:*:*:*
    • cpe:2.3:a:http-body_project:http-body:1.01:*:*:*:*:*:*:*
    • cpe:2.3:a:http-body_project:http-body:1.02:*:*:*:*:*:*:*
    • cpe:2.3:a:http-body_project:http-body:1.03:*:*:*:*:*:*:*
    • cpe:2.3:a:http-body_project:http-body:1.04:*:*:*:*:*:*:*
    • cpe:2.3:a:http-body_project:http-body:1.05:*:*:*:*:*:*:*
    • cpe:2.3:a:http-body_project:http-body:1.06:*:*:*:*:*:*:*
    • cpe:2.3:a:http-body_project:http-body:1.07:*:*:*:*:*:*:*
    • cpe:2.3:a:http-body_project:http-body:1.08:*:*:*:*:*:*:*
    • cpe:2.3:a:http-body_project:http-body:1.09:*:*:*:*:*:*:*
    • cpe:2.3:a:http-body_project:http-body:1.10:*:*:*:*:*:*:*
    • cpe:2.3:a:http-body_project:http-body:1.11:*:*:*:*:*:*:*
    • cpe:2.3:a:http-body_project:http-body:1.12:*:*:*:*:*:*:*
    • cpe:2.3:a:http-body_project:http-body:1.14:*:*:*:*:*:*:*
    • cpe:2.3:a:http-body_project:http-body:1.15:*:*:*:*:*:*:*
    • cpe:2.3:a:http-body_project:http-body:1.16:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.