6.8

CVE-2013-4407

HTTP::Body::Multipart in the HTTP-Body module for Perl (1.07 through 1.22, before 1.23) uses the part of the uploaded file's name after the first "." character as the suffix of a temporary file, which makes it easier for remote attackers to conduct attacks by leveraging subsequent behavior that may assume the suffix is well-formed.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Http-body ProjectHttp-body Version <= 1.17
Http-body ProjectHttp-body Version0.01
Http-body ProjectHttp-body Version0.2
Http-body ProjectHttp-body Version0.03
Http-body ProjectHttp-body Version0.4
Http-body ProjectHttp-body Version0.5
Http-body ProjectHttp-body Version0.6
Http-body ProjectHttp-body Version0.7
Http-body ProjectHttp-body Version0.8
Http-body ProjectHttp-body Version0.9
Http-body ProjectHttp-body Version1.00
Http-body ProjectHttp-body Version1.01
Http-body ProjectHttp-body Version1.02
Http-body ProjectHttp-body Version1.03
Http-body ProjectHttp-body Version1.04
Http-body ProjectHttp-body Version1.05
Http-body ProjectHttp-body Version1.06
Http-body ProjectHttp-body Version1.07
Http-body ProjectHttp-body Version1.08
Http-body ProjectHttp-body Version1.09
Http-body ProjectHttp-body Version1.10
Http-body ProjectHttp-body Version1.11
Http-body ProjectHttp-body Version1.12
Http-body ProjectHttp-body Version1.14
Http-body ProjectHttp-body Version1.15
Http-body ProjectHttp-body Version1.16
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.83% 0.735
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.