Mutiny < 5.0-1.11 Multiple Directory Traversals

high Nessus Plugin ID 66497

Synopsis

The remote host contains a network monitoring application that is affected by multiple directory traversal vulnerabilities.

Description

The remote server hosts a version of Mutiny prior to 5.0-1.11. It is, therefore, reportedly affected by multiple directory traversal vulnerabilities that could allow an authenticated attacker to upload, delete, and move files on the remote system with root privileges. The functions for UPLOAD, DELETE, CUT, and COPY used in the 'Documents' section of the web frontend of Mutiny are affected.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to version 5.0-1.11 or later.

See Also

http://www.nessus.org/u?cc5972a2

Plugin Details

Severity: High

ID: 66497

File Name: mutiny_5_0_1_11.nasl

Version: 1.8

Type: remote

Family: CGI abuses

Published: 5/17/2013

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.4

CVSS v2

Risk Factor: High

Base Score: 8.5

Temporal Score: 7

Vector: CVSS2#AV:N/AC:M/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2013-0136

Vulnerability Information

CPE: cpe:/a:mutiny:standard

Required KB Items: www/mutiny

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 5/15/2013

Vulnerability Publication Date: 5/15/2013

Exploitable With

Metasploit (Mutiny 5 Arbitrary File Upload)

Reference Information

CVE: CVE-2013-0136

BID: 59883

CERT: 701572