A vulnerability in ACME mini_httpd before version 1.30 allows remote attackers to read arbitrary files on the server. The flaw is due to insufficient validation of user-supplied input, enabling directory traversal attacks that bypass intended access controls.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone proof-of-concept exploit for CVE-2018-18778 affecting ACME mini_httpd before version 1.30. The repo contains two files: a README describing the vulnerability and mitigation, and a single Python exploit script, exploit.py, which is the operational entry point. The exploit’s core capability is remote arbitrary file read over HTTP. It accepts a target base URL, appends an attacker-supplied absolute file path (default /etc/passwd), and sends a GET request using the requests library with an intentionally empty Host header (headers={"Host": ""}). The script disables TLS certificate verification and uses a configurable timeout. Returned content is printed directly; if the output resembles passwd-format data, it is colorized for readability and the script heuristically marks the attempt as successful when strings like "root:" or "bin:" are present. Structurally, the code is simple: ExploitACME.read_file() performs the malicious request, colorize_passwd_line() formats passwd-like output, and main() handles CLI parsing and user interaction. There is no post-exploitation, persistence, brute force, or command execution logic. This is not a detection-only script; it actively attempts exploitation and retrieves file contents if the target is vulnerable. The exploit is best classified as OPERATIONAL because it contains a working payload but only for a narrow, hardcoded abuse case centered on arbitrary file disclosure.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.