A directory traversal vulnerability exists in wkhtmltopdf through version 0.12.5. Remote attackers can exploit this flaw by providing a crafted HTML file, which, when processed by wkhtmltopdf with default configurations, allows unauthorized reading of arbitrary local files, leading to disclosure of sensitive information.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single file, 'index.html', which is actually a PHP-enabled HTML file. The file includes a PHP snippet that issues an HTTP header to redirect the client to 'file:///etc/passwd'. This is a proof-of-concept (POC) exploit demonstrating a potential file disclosure or open redirect vulnerability on PHP web servers. The exploit attempts to leverage the browser's handling of file URIs to access the sensitive '/etc/passwd' file on the server. The repository is minimal, containing only this file, and is intended to demonstrate the impact of improper output handling or misconfigured web servers that execute PHP code in files with non-standard extensions.
This repository contains two HTML files, 'passwd' and 'pwn.html', both designed to demonstrate browser-based local file read and network access techniques. The 'passwd' file uses iframes to attempt to load and display the contents of '/etc/passwd' from the local filesystem, as well as to access remote (http://94.237.48.12:44482/) and local (http://127.0.0.1/) web resources. The 'pwn.html' file uses JavaScript (XMLHttpRequest) to attempt to read '/etc/passwd' and display its contents in the browser. These files serve as proof-of-concept exploits for local file read vulnerabilities or misconfigurations in browser security policies. No specific CVE or product is targeted, but the code demonstrates the risk of file:// URI access and cross-origin resource loading in browsers.
This repository contains a single file, index.php, which is a minimal PHP web page. The main exploit capability is to use the PHP header() function to send an HTTP redirect to the file URI 'file:///etc//passwd'. This attempts to make the browser or client access the /etc/passwd file on the server. The exploit is a proof-of-concept (POC) for a local file disclosure via HTTP redirection, targeting Linux systems running PHP web applications. The repository is very simple, containing only this exploit code, and does not include any payload customization or advanced features.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.