HTTP::Body::Multipart in the HTTP-Body 1.08, 1.17, and earlier module for Perl uses the part of the uploaded file's name after the first "." character as the suffix of a temporary file, which makes it easier for remote attackers to conduct attacks by leveraging subsequent behavior that may assume the suffix is well-formed.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2013-11-23 10:55
Updated : 2014-03-31 23:23
NVD link : CVE-2013-4407
Mitre link : CVE-2013-4407
JSON object : View
CWE
Products Affected
http-body_project
- http-body