HTTP::Body::Multipart in the HTTP-Body module for Perl (1.07 through 1.22, before 1.23) uses the part of the uploaded file's name after the first "." character as the suffix of a temporary file, which makes it easier for remote attackers to conduct attacks by leveraging subsequent behavior that may assume the suffix is well-formed.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2013-11-23 18:55
Updated : 2024-05-01 18:15
NVD link : CVE-2013-4407
Mitre link : CVE-2013-4407
CVE.ORG link : CVE-2013-4407
JSON object : View
Products Affected
http-body_project
- http-body
CWE