CVE-2013-0136

Mutiny < 5.0-1.11 - Authenticated Path Traversal and Arbitrary File Write via EditDocument Servlet

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2013-0136. PoCs published by Metasploit, juan vazquez, including Metasploit module auxiliary/admin/http/mutiny_frontend_read_delete.

AI-analyzed exploit summary This Metasploit module exploits a directory traversal vulnerability in Mutiny 5's EditDocument servlet to upload arbitrary files, leading to remote code execution with root privileges. It authenticates as a valid user, uploads an ELF payload and a JSP file to execute it, and triggers the payload via HTTP request.

Description

Multiple directory traversal vulnerabilities in the EditDocument servlet in the Frontend in Mutiny before 5.0-1.11 allow remote authenticated users to upload and execute arbitrary programs, read arbitrary files, or cause a denial of service (file deletion or renaming) via (1) the uploadPath parameter in an UPLOAD operation; the paths[] parameter in a (2) DELETE, (3) CUT, or (4) COPY operation; or the newPath parameter in a (5) CUT or (6) COPY operation.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotelinux
https://www.exploit-db.com/exploits/25517

This Metasploit module exploits a directory traversal vulnerability in Mutiny 5's EditDocument servlet to upload arbitrary files, leading to remote code execution with root privileges. It authenticates as a valid user, uploads an ELF payload and a JSP file to execute it, and triggers the payload via HTTP request.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Mutiny 5.0-1.07 Appliance
Auth required
Prerequisites: Valid Mutiny web frontend credentials · Network access to the Mutiny appliance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC
by juan vazquez · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/http/mutiny_frontend_read_delete.rb

This Metasploit module exploits a directory traversal vulnerability in the Mutiny 5 appliance's EditDocument servlet, allowing authenticated users to read or delete arbitrary files with root privileges. It includes authentication handling and file operations via crafted POST requests.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Mutiny 5.0-1.07
Auth required
Prerequisites: Valid frontend user credentials · Network access to the Mutiny appliance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by juan vazquez · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/mutiny_frontend_upload.rb

This Metasploit module exploits a directory traversal vulnerability in Mutiny 5's EditDocument servlet to upload arbitrary files, leading to remote code execution with root privileges. It authenticates as a valid user, uploads an ELF payload and a JSP file to execute it.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Mutiny 5.0-1.07
Auth required
Prerequisites: Valid Mutiny 5 web frontend credentials · Network access to the target appliance
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/701572

Scores

EPSS 0.7214
EPSS Percentile 98.8%

Details

CWE
CWE-22
Status published
Products (4)
mutiny/mutiny 5.0-1.00
mutiny/mutiny < 5.0-1.10
mutiny/mutiny_appliance
mutiny/mutiny_virtual_appliance
Published Jun 01, 2013
Tracked Since Feb 18, 2026