Multiple directory traversal vulnerabilities in the EditDocument servlet in the Frontend in Mutiny before 5.0-1.11 allow remote authenticated users to upload and execute arbitrary programs, read arbitrary files, or cause a denial of service (file deletion or renaming) via (1) the uploadPath parameter in an UPLOAD operation; the paths[] parameter in a (2) DELETE, (3) CUT, or (4) COPY operation; or the newPath parameter in a (5) CUT or (6) COPY operation.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2024-09-17T02:48:04.090Z
Reserved: 2012-12-06T00:00:00Z
Link: CVE-2013-0136
No data.
Status : Deferred
Published: 2013-06-01T14:21:05.813
Modified: 2025-04-11T00:51:21.963
Link: CVE-2013-0136
No data.
OpenCVE Enrichment
No data.
Weaknesses