CVE-2013-0136 is a set of directory traversal vulnerabilities in the EditDocument servlet in the Frontend component of Mutiny before version 5.0-1.11. The vulnerable operations are UPLOAD, DELETE, CUT, and COPY. Specifically, attacker-controlled path values supplied via the uploadPath parameter in UPLOAD, the paths[] parameter in DELETE, CUT, and COPY, and the newPath parameter in CUT and COPY are not properly restricted to intended directories. A remote authenticated user can exploit these path traversal flaws to escape the expected file-management scope and perform unauthorized filesystem operations, including uploading and executing arbitrary programs, reading arbitrary files, and deleting or renaming files.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module (mutiny_frontend_upload.rb) that exploits an arbitrary file upload vulnerability in the Mutiny 5 appliance (CVE-2013-0136). The exploit targets the EditDocument servlet, which allows authenticated users to upload files. Due to a directory traversal flaw, attackers can upload files to arbitrary locations, leading to remote code execution as root. The module first authenticates using provided credentials, uploads a Linux ELF payload to /tmp, then uploads a JSP webshell to the Tomcat webapps directory to execute the payload. The exploit is weaponized, allowing customizable payloads and automated cleanup. The main attack vector is network-based, targeting the HTTP interface of the Mutiny appliance. The code is written in Ruby and is designed to be used within the Metasploit framework.
This repository contains a single Metasploit auxiliary module targeting the Mutiny 5 appliance (version 5.0-1.07). The module exploits a directory traversal vulnerability in the EditDocument servlet of the Mutiny web frontend, allowing any authenticated user to read or delete arbitrary files on the system with root privileges. The exploit works by sending crafted HTTP POST requests to the /interface/EditDocument endpoint, using directory traversal sequences to specify files outside the intended directory. The module requires valid frontend user credentials and interacts with several HTTP endpoints for authentication and exploitation. The main capabilities are arbitrary file read and delete, with the ability to retrieve file contents via the web interface. The code is written in Ruby and is structured as a standard Metasploit module, making it easy to use within the Metasploit framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.