CVE-2013-0136 describes multiple directory traversal vulnerabilities in the EditDocument servlet of Mutiny before version 5.0-1.11, affecting Mutiny, Mutiny Appliance, and Mutiny Virtual Appliance products. This vulnerability allows remote authenticated attackers to upload and execute arbitrary programs, read arbitrary files, or cause denial of service through file deletion or renaming. With a CVSS score of 8.5, it is considered highly severe due to its network-based attack vector, medium attack complexity, and complete compromise of confidentiality, integrity, and availability. While not on the KEV catalog or Hot List, exploit modules are available in Metasploit and ExploitDB, indicating readily available exploit code, despite a lack of community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.0-1.10CPE matchmatch criteria | cpe:2.3:a:mutiny:mutiny:*:*:*:*:*:*:*:* | ||
5.0-1.00CPE matchmatch criteria | cpe:2.3:a:mutiny:mutiny:5.0-1.00:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:mutiny:mutiny_virtual_appliance:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:mutiny:mutiny_appliance:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:S/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.