6.8
CVE-2013-4407
- EPSS 0.83%
- Veröffentlicht 23.11.2013 18:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
HTTP::Body::Multipart in the HTTP-Body module for Perl (1.07 through 1.22, before 1.23) uses the part of the uploaded file's name after the first "." character as the suffix of a temporary file, which makes it easier for remote attackers to conduct attacks by leveraging subsequent behavior that may assume the suffix is well-formed.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Http-body Project ≫ Http-body Version <= 1.17
Http-body Project ≫ Http-body Version0.01
Http-body Project ≫ Http-body Version0.2
Http-body Project ≫ Http-body Version0.03
Http-body Project ≫ Http-body Version0.4
Http-body Project ≫ Http-body Version0.5
Http-body Project ≫ Http-body Version0.6
Http-body Project ≫ Http-body Version0.7
Http-body Project ≫ Http-body Version0.8
Http-body Project ≫ Http-body Version0.9
Http-body Project ≫ Http-body Version1.00
Http-body Project ≫ Http-body Version1.01
Http-body Project ≫ Http-body Version1.02
Http-body Project ≫ Http-body Version1.03
Http-body Project ≫ Http-body Version1.04
Http-body Project ≫ Http-body Version1.05
Http-body Project ≫ Http-body Version1.06
Http-body Project ≫ Http-body Version1.07
Http-body Project ≫ Http-body Version1.08
Http-body Project ≫ Http-body Version1.09
Http-body Project ≫ Http-body Version1.10
Http-body Project ≫ Http-body Version1.11
Http-body Project ≫ Http-body Version1.12
Http-body Project ≫ Http-body Version1.14
Http-body Project ≫ Http-body Version1.15
Http-body Project ≫ Http-body Version1.16
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.83% | 0.735 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|