Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2013-0136

EPSS 72.14% · P99
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2013-0136

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Multiple directory traversal vulnerabilities in the EditDocument servlet in the Frontend in Mutiny before 5.0-1.11 allow remote authenticated users to upload and execute arbitrary programs, read arbitrary files, or cause a denial of service (file deletion or renaming) via (1) the uploadPath parameter in an UPLOAD operation; the paths[] parameter in a (2) DELETE, (3) CUT, or (4) COPY operation; or the newPath parameter in a (5) CUT or (6) COPY operation.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Mutiny 多个目录遍历漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Mutiny是英国Mutiny公司的一个网络监控设备。 Mutiny 5.0-1.11之前的版本中的Frontend中的EditDocument servlet中存在多个目录遍历漏洞。远程经过授权的攻击者可通过(1)UPLOAD操作中的uploadPath参数;(2)DELETE,(3)CUT或(4)COPY操作中的paths[]参数;或(5)CUT或(6)COPY操作中的newPath参数利用这些漏洞上传任意程序,读取任意文件,或造成拒绝服务(文件删除或重命名)。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2013-0136

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2013-0136

登录查看更多情报信息。

Same Patch Batch · n/a · 2013-06-01 · 5 CVEs total

CVE-2012-3544Apache Tomcat 输入验证错误漏洞
CVE-2013-2067Apache Tomcat 授权问题漏洞
CVE-2013-2071Apache Tomcat 信息泄露漏洞
CVE-2013-3261WordPress GRAND FlAGallery插件“s”跨站脚本漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2013-0136

No comments yet


Leave a comment