{"api_version":"1","generated_at":"2026-07-23T08:13:29+00:00","cve":"CVE-2013-4407","urls":{"html":"https://cve.report/CVE-2013-4407","api":"https://cve.report/api/cve/CVE-2013-4407.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2013-4407","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2013-4407"},"summary":{"title":"CVE-2013-4407","description":"HTTP::Body::Multipart in the HTTP-Body module for Perl (1.07 through 1.22, before 1.23) uses the part of the uploaded file's name after the first \".\" character as the suffix of a temporary file, which makes it easier for remote attackers to conduct attacks by leveraging subsequent behavior that may assume the suffix is well-formed.","state":"PUBLISHED","assigner":"redhat","published_at":"2013-11-23 18:55:04","updated_at":"2026-04-29 01:13:23"},"problem_types":["NVD-CWE-noinfo","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://git.shadowcat.co.uk/gitweb/gitweb.cgi?p=catagits/HTTP-Body.git%3Ba=commit%3Bh=cc75c886256f187cda388641931e8dafad6c2346","name":"http://git.shadowcat.co.uk/gitweb/gitweb.cgi?p=catagits/HTTP-Body.git%3Ba=commit%3Bh=cc75c886256f187cda388641931e8dafad6c2346","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://git.shadowcat.co.uk/gitweb/gitweb.cgi?p=catagits/HTTP-Body.git%3Ba=commit%3Bh=13ac5b23c083bc56e32dd706ca02fca292bd2161","name":"http://git.shadowcat.co.uk/gitweb/gitweb.cgi?p=catagits/HTTP-Body.git%3Ba=commit%3Bh=13ac5b23c083bc56e32dd706ca02fca292bd2161","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=721634","name":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=721634","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"#721634 - libhttp-body-perl: CVE-2013-4407: HTTP::Body::Multipart critical security bug - Debian Bug report logs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://metacpan.org/release/GETTY/HTTP-Body-1.23/","name":"https://metacpan.org/release/GETTY/HTTP-Body-1.23/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.openwall.com/lists/oss-security/2024/04/07/1","name":"https://www.openwall.com/lists/oss-security/2024/04/07/1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://www.debian.org/security/2013/dsa-2801","name":"http://www.debian.org/security/2013/dsa-2801","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Debian -- Security Information -- DSA-2801-1 libhttp-body-perl","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2024/04/07/1","name":"http://www.openwall.com/lists/oss-security/2024/04/07/1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00018.html","name":"http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00018.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[security-announce] openSUSE-SU-2014:0433-1: important: perl-HTTP-Body:","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://git.shadowcat.co.uk/gitweb/gitweb.cgi?p=catagits/HTTP-Body.git;a=commit;h=13ac5b23c083bc56e32dd706ca02fca292bd2161","name":":http://git.shadowcat.co.uk/gitweb/gitweb.cgi?p=catagits/HTTP-Body.git;a=commit;h=13ac5b23c083bc56e32dd706ca02fca292bd2161","refsource":"MITRE","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://git.shadowcat.co.uk/gitweb/gitweb.cgi?p=catagits/HTTP-Body.git;a=commit;h=cc75c886256f187cda388641931e8dafad6c2346","name":":http://git.shadowcat.co.uk/gitweb/gitweb.cgi?p=catagits/HTTP-Body.git;a=commit;h=cc75c886256f187cda388641931e8dafad6c2346","refsource":"MITRE","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2013-4407","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2013-4407","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2013","cve_id":"4407","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"http-body_project","cpe5":"http-body","cpe6":"0.01","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4407","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"http-body_project","cpe5":"http-body","cpe6":"0.03","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4407","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"http-body_project","cpe5":"http-body","cpe6":"0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4407","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"http-body_project","cpe5":"http-body","cpe6":"0.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4407","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"http-body_project","cpe5":"http-body","cpe6":"0.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4407","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"http-body_project","cpe5":"http-body","cpe6":"0.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4407","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"http-body_project","cpe5":"http-body","cpe6":"0.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4407","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"http-body_project","cpe5":"http-body","cpe6":"0.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4407","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"http-body_project","cpe5":"http-body","cpe6":"0.9","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4407","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"http-body_project","cpe5":"http-body","cpe6":"1.00","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4407","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"http-body_project","cpe5":"http-body","cpe6":"1.01","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4407","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"http-body_project","cpe5":"http-body","cpe6":"1.02","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4407","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"http-body_project","cpe5":"http-body","cpe6":"1.03","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4407","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"http-body_project","cpe5":"http-body","cpe6":"1.04","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4407","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"http-body_project","cpe5":"http-body","cpe6":"1.05","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4407","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"http-body_project","cpe5":"http-body","cpe6":"1.06","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4407","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"http-body_project","cpe5":"http-body","cpe6":"1.07","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4407","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"http-body_project","cpe5":"http-body","cpe6":"1.08","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4407","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"http-body_project","cpe5":"http-body","cpe6":"1.09","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4407","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"http-body_project","cpe5":"http-body","cpe6":"1.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4407","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"http-body_project","cpe5":"http-body","cpe6":"1.11","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4407","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"http-body_project","cpe5":"http-body","cpe6":"1.12","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4407","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"http-body_project","cpe5":"http-body","cpe6":"1.14","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4407","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"http-body_project","cpe5":"http-body","cpe6":"1.15","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4407","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"http-body_project","cpe5":"http-body","cpe6":"1.16","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4407","vulnerable":"1","versionEndIncluding":"1.17","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"http-body_project","cpe5":"http-body","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2013","cve_id":"4407","cve":"CVE-2013-4407","epss":"0.008300000","percentile":"0.746070000","score_date":"2026-04-29","updated_at":"2026-04-30 00:13:22"},"legacy_qids":[{"cve":"CVE-2013-4407","qid":"510799","title":"Alpine Linux Security Update for perl-http-body"},{"cve":"CVE-2013-4407","qid":"510800","title":"Alpine Linux Security Update for perl-http-body"},{"cve":"CVE-2013-4407","qid":"510801","title":"Alpine Linux Security Update for perl-http-body"}]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T16:45:14.008Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_transferred"],"url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=721634"},{"tags":["x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00018.html"},{"tags":["x_transferred"],"url":"http://www.debian.org/security/2013/dsa-2801"},{"tags":["x_transferred"],"url":"https://metacpan.org/release/GETTY/HTTP-Body-1.23/"},{"tags":["x_transferred"],"url":"https://www.openwall.com/lists/oss-security/2024/04/07/1"},{"tags":["x_transferred"],"url":"http://git.shadowcat.co.uk/gitweb/gitweb.cgi?p=catagits/HTTP-Body.git%3Ba=commit%3Bh=13ac5b23c083bc56e32dd706ca02fca292bd2161"},{"tags":["x_transferred"],"url":"http://git.shadowcat.co.uk/gitweb/gitweb.cgi?p=catagits/HTTP-Body.git%3Ba=commit%3Bh=cc75c886256f187cda388641931e8dafad6c2346"},{"name":"[oss-security] 20240407 HTTP::Body before 1.23 for Perl is still vulnerable to CVE-2013-4407","tags":["mailing-list","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2024/04/07/1"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2013-09-02T00:00:00.000Z","descriptions":[{"lang":"en","value":"HTTP::Body::Multipart in the HTTP-Body module for Perl (1.07 through 1.22, before 1.23) uses the part of the uploaded file's name after the first \".\" character as the suffix of a temporary file, which makes it easier for remote attackers to conduct attacks by leveraging subsequent behavior that may assume the suffix is well-formed."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2024-05-01T18:06:46.936Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=721634"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00018.html"},{"url":"http://www.debian.org/security/2013/dsa-2801"},{"url":"https://metacpan.org/release/GETTY/HTTP-Body-1.23/"},{"url":"https://www.openwall.com/lists/oss-security/2024/04/07/1"},{"url":"http://git.shadowcat.co.uk/gitweb/gitweb.cgi?p=catagits/HTTP-Body.git%3Ba=commit%3Bh=13ac5b23c083bc56e32dd706ca02fca292bd2161"},{"url":"http://git.shadowcat.co.uk/gitweb/gitweb.cgi?p=catagits/HTTP-Body.git%3Ba=commit%3Bh=cc75c886256f187cda388641931e8dafad6c2346"},{"name":"[oss-security] 20240407 HTTP::Body before 1.23 for Perl is still vulnerable to CVE-2013-4407","tags":["mailing-list"],"url":"http://www.openwall.com/lists/oss-security/2024/04/07/1"}]}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2013-4407","datePublished":"2013-11-23T00:00:00.000Z","dateReserved":"2013-06-12T00:00:00.000Z","dateUpdated":"2024-08-06T16:45:14.008Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2013-11-23 18:55:04","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:http-body_project:http-body:*:*:*:*:*:*:*:*","versionEndIncluding":"1.17","matchCriteriaId":"28144E4C-E5E1-4C2E-871C-4DA6BF480D3F"},{"vulnerable":true,"criteria":"cpe:2.3:a:http-body_project:http-body:0.01:*:*:*:*:*:*:*","matchCriteriaId":"086FF56C-5540-4C7B-B4FA-898D9694A221"},{"vulnerable":true,"criteria":"cpe:2.3:a:http-body_project:http-body:0.2:*:*:*:*:*:*:*","matchCriteriaId":"7E279C36-F0F7-48D9-818E-A9554D724C93"},{"vulnerable":true,"criteria":"cpe:2.3:a:http-body_project:http-body:0.03:*:*:*:*:*:*:*","matchCriteriaId":"800CA924-E48F-484C-A280-3139535597F3"},{"vulnerable":true,"criteria":"cpe:2.3:a:http-body_project:http-body:0.4:*:*:*:*:*:*:*","matchCriteriaId":"E723BE34-7F32-4CF8-B356-5D3158097BB7"},{"vulnerable":true,"criteria":"cpe:2.3:a:http-body_project:http-body:0.5:*:*:*:*:*:*:*","matchCriteriaId":"C7AD5F14-FB2A-4E3B-9D18-0BCBFB24FA10"},{"vulnerable":true,"criteria":"cpe:2.3:a:http-body_project:http-body:0.6:*:*:*:*:*:*:*","matchCriteriaId":"5D4DD326-1C66-452B-AAE2-BFA237578C2B"},{"vulnerable":true,"criteria":"cpe:2.3:a:http-body_project:http-body:0.7:*:*:*:*:*:*:*","matchCriteriaId":"319023AD-9A20-4210-97F6-A7E4BCC42A74"},{"vulnerable":true,"criteria":"cpe:2.3:a:http-body_project:http-body:0.8:*:*:*:*:*:*:*","matchCriteriaId":"5C33540B-3D28-413C-871C-AC7D19A98DAA"},{"vulnerable":true,"criteria":"cpe:2.3:a:http-body_project:http-body:0.9:*:*:*:*:*:*:*","matchCriteriaId":"1505FC6C-83EB-4999-92DB-D3CA15332265"},{"vulnerable":true,"criteria":"cpe:2.3:a:http-body_project:http-body:1.00:*:*:*:*:*:*:*","matchCriteriaId":"9AD7F3A4-86ED-46C1-8DDF-049C6399FA53"},{"vulnerable":true,"criteria":"cpe:2.3:a:http-body_project:http-body:1.01:*:*:*:*:*:*:*","matchCriteriaId":"D113F676-7AED-4360-B91A-38F40C011009"},{"vulnerable":true,"criteria":"cpe:2.3:a:http-body_project:http-body:1.02:*:*:*:*:*:*:*","matchCriteriaId":"0C2371FE-DDFD-47B9-B938-10C11379A869"},{"vulnerable":true,"criteria":"cpe:2.3:a:http-body_project:http-body:1.03:*:*:*:*:*:*:*","matchCriteriaId":"1D0A64C0-A6BF-45A4-8C66-BB7AEB5FD387"},{"vulnerable":true,"criteria":"cpe:2.3:a:http-body_project:http-body:1.04:*:*:*:*:*:*:*","matchCriteriaId":"DB0DA4BA-AECA-40E0-8043-9E7FD11AC1CA"},{"vulnerable":true,"criteria":"cpe:2.3:a:http-body_project:http-body:1.05:*:*:*:*:*:*:*","matchCriteriaId":"03E2FE36-6761-4668-89A5-89AA4FD4A2A9"},{"vulnerable":true,"criteria":"cpe:2.3:a:http-body_project:http-body:1.06:*:*:*:*:*:*:*","matchCriteriaId":"580827C1-57C3-4936-9D01-E6F81203DC3A"},{"vulnerable":true,"criteria":"cpe:2.3:a:http-body_project:http-body:1.07:*:*:*:*:*:*:*","matchCriteriaId":"2D94B321-EB9B-4A20-9791-B9F3EA77FC40"},{"vulnerable":true,"criteria":"cpe:2.3:a:http-body_project:http-body:1.08:*:*:*:*:*:*:*","matchCriteriaId":"1660BB88-C4FF-4893-B224-BDD8E6F2903D"},{"vulnerable":true,"criteria":"cpe:2.3:a:http-body_project:http-body:1.09:*:*:*:*:*:*:*","matchCriteriaId":"7EE71FDF-EEF5-4A12-A9E5-26C6BB4C503B"},{"vulnerable":true,"criteria":"cpe:2.3:a:http-body_project:http-body:1.10:*:*:*:*:*:*:*","matchCriteriaId":"5B37AFF2-42A5-4907-BCA7-D9AA52B9C232"},{"vulnerable":true,"criteria":"cpe:2.3:a:http-body_project:http-body:1.11:*:*:*:*:*:*:*","matchCriteriaId":"E00D95DB-F47A-49D0-8DAC-AEE45BC3E424"},{"vulnerable":true,"criteria":"cpe:2.3:a:http-body_project:http-body:1.12:*:*:*:*:*:*:*","matchCriteriaId":"2E3FB0FD-DF10-4935-A949-79110330275E"},{"vulnerable":true,"criteria":"cpe:2.3:a:http-body_project:http-body:1.14:*:*:*:*:*:*:*","matchCriteriaId":"82011B9A-ACF3-47EE-9323-8CF8A2286EE5"},{"vulnerable":true,"criteria":"cpe:2.3:a:http-body_project:http-body:1.15:*:*:*:*:*:*:*","matchCriteriaId":"2821586B-223D-43BB-90EB-D268A573FE2F"},{"vulnerable":true,"criteria":"cpe:2.3:a:http-body_project:http-body:1.16:*:*:*:*:*:*:*","matchCriteriaId":"998BEBCF-BFA2-46A4-BE38-34EADBE4D964"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2013","CveId":"4407","Ordinal":"1","Title":"CVE-2013-4407","CVE":"CVE-2013-4407","Year":"2013"},"notes":[{"CveYear":"2013","CveId":"4407","Ordinal":"1","NoteData":"HTTP::Body::Multipart in the HTTP-Body module for Perl (1.07 through 1.22, before 1.23) uses the part of the uploaded file's name after the first \".\" character as the suffix of a temporary file, which makes it easier for remote attackers to conduct attacks by leveraging subsequent behavior that may assume the suffix is well-formed.","Type":"Description","Title":"CVE-2013-4407"},{"CveYear":"2013","CveId":"4407","Ordinal":"2","NoteData":"2013-11-23","Type":"Other","Title":"Published"},{"CveYear":"2013","CveId":"4407","Ordinal":"3","NoteData":"2014-03-27","Type":"Other","Title":"Modified"}]}}}