CVE-2013-4407
Last modified
CVE-2013-4407 is a vulnerability of currently unknown severity. HTTP::Body::Multipart in the HTTP-Body module for Perl (1.07 through 1.22, before 1.23) uses the part of the uploaded file's name after the first "." character as the suffix of a temporary file, which makes it easier for remote attackers to conduct attacks by leveraging subsequent behavior that may assume the suffix is well-formed.. EPSS estimates a 2.88% chance of exploitation in the next 30 days.
Description
HTTP::Body::Multipart in the HTTP-Body module for Perl (1.07 through 1.22, before 1.23) uses the part of the uploaded file's name after the first "." character as the suffix of a temporary file, which makes it easier for remote attackers to conduct attacks by leveraging subsequent behavior that may assume the suffix is well-formed.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Http-Body Project | Http-Body | <= 1.17 |
| Http-Body Project | Http-Body | 0.01 |
| Http-Body Project | Http-Body | 0.2 |
| Http-Body Project | Http-Body | 0.03 |
| Http-Body Project | Http-Body | 0.4 |
| Http-Body Project | Http-Body | 0.5 |
| Http-Body Project | Http-Body | 0.6 |
| Http-Body Project | Http-Body | 0.7 |
| Http-Body Project | Http-Body | 0.8 |
| Http-Body Project | Http-Body | 0.9 |
| Http-Body Project | Http-Body | 1.00 |
| Http-Body Project | Http-Body | 1.01 |
| Http-Body Project | Http-Body | 1.02 |
| Http-Body Project | Http-Body | 1.03 |
| Http-Body Project | Http-Body | 1.04 |
| Http-Body Project | Http-Body | 1.05 |
| Http-Body Project | Http-Body | 1.06 |
| Http-Body Project | Http-Body | 1.07 |
| Http-Body Project | Http-Body | 1.08 |
| Http-Body Project | Http-Body | 1.09 |
| Http-Body Project | Http-Body | 1.10 |
| Http-Body Project | Http-Body | 1.11 |
| Http-Body Project | Http-Body | 1.12 |
| Http-Body Project | Http-Body | 1.14 |
| Http-Body Project | Http-Body | 1.15 |
| Http-Body Project | Http-Body | 1.16 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-4407?
How severe is CVE-2013-4407?
How do I fix CVE-2013-4407?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-4401The virConnectDomainXMLToNative API function in libvirt 1.1.…
- CVE-2013-4402The compressed packet parser in GnuPG 1.4.x before 1.4.15 an…
- CVE-2013-4403Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2013-4404cumin in Red Hat Enterprise MRG Grid 2.4 does not properly e…
- CVE-2013-4405Multiple cross-site request forgery (CSRF) vulnerabilities i…
- CVE-2013-4406The Quick Tabs module 6.x-2.x before 6.x-2.2, 6.x-3.x before…
- CVE-2013-4408Heap-based buffer overflow in the dcerpc_read_ncacn_packet_d…
- CVE-2013-4409An eval() vulnerability exists in Python Software Foundation…9.8
- CVE-2013-4410ReviewBoard: has an access-control problem in REST API7.5
- CVE-2013-4411Review Board: URL processing gives unauthorized users access…4.3
- CVE-2013-4412slim has NULL pointer dereference when using crypt() method …7.5
- CVE-2013-4413Directory traversal vulnerability in controller/concerns/ren…
Are you affected by CVE-2013-4407?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
