Unrated severityNVD Advisory· Published Nov 23, 2013· Updated Apr 29, 2026
CVE-2013-4407
CVE-2013-4407
Description
HTTP::Body::Multipart in the HTTP-Body module for Perl (1.07 through 1.22, before 1.23) uses the part of the uploaded file's name after the first "." character as the suffix of a temporary file, which makes it easier for remote attackers to conduct attacks by leveraging subsequent behavior that may assume the suffix is well-formed.
Affected products
26cpe:2.3:a:http-body_project:http-body:*:*:*:*:*:*:*:*+ 25 more
- cpe:2.3:a:http-body_project:http-body:*:*:*:*:*:*:*:*range: <=1.17
- cpe:2.3:a:http-body_project:http-body:0.01:*:*:*:*:*:*:*
- cpe:2.3:a:http-body_project:http-body:0.03:*:*:*:*:*:*:*
- cpe:2.3:a:http-body_project:http-body:0.2:*:*:*:*:*:*:*
- cpe:2.3:a:http-body_project:http-body:0.4:*:*:*:*:*:*:*
- cpe:2.3:a:http-body_project:http-body:0.5:*:*:*:*:*:*:*
- cpe:2.3:a:http-body_project:http-body:0.6:*:*:*:*:*:*:*
- cpe:2.3:a:http-body_project:http-body:0.7:*:*:*:*:*:*:*
- cpe:2.3:a:http-body_project:http-body:0.8:*:*:*:*:*:*:*
- cpe:2.3:a:http-body_project:http-body:0.9:*:*:*:*:*:*:*
- cpe:2.3:a:http-body_project:http-body:1.00:*:*:*:*:*:*:*
- cpe:2.3:a:http-body_project:http-body:1.01:*:*:*:*:*:*:*
- cpe:2.3:a:http-body_project:http-body:1.02:*:*:*:*:*:*:*
- cpe:2.3:a:http-body_project:http-body:1.03:*:*:*:*:*:*:*
- cpe:2.3:a:http-body_project:http-body:1.04:*:*:*:*:*:*:*
- cpe:2.3:a:http-body_project:http-body:1.05:*:*:*:*:*:*:*
- cpe:2.3:a:http-body_project:http-body:1.06:*:*:*:*:*:*:*
- cpe:2.3:a:http-body_project:http-body:1.07:*:*:*:*:*:*:*
- cpe:2.3:a:http-body_project:http-body:1.08:*:*:*:*:*:*:*
- cpe:2.3:a:http-body_project:http-body:1.09:*:*:*:*:*:*:*
- cpe:2.3:a:http-body_project:http-body:1.10:*:*:*:*:*:*:*
- cpe:2.3:a:http-body_project:http-body:1.11:*:*:*:*:*:*:*
- cpe:2.3:a:http-body_project:http-body:1.12:*:*:*:*:*:*:*
- cpe:2.3:a:http-body_project:http-body:1.14:*:*:*:*:*:*:*
- cpe:2.3:a:http-body_project:http-body:1.15:*:*:*:*:*:*:*
- cpe:2.3:a:http-body_project:http-body:1.16:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6News mentions
0No linked articles in our index yet.