Torrentpier version 2.4.1 is vulnerable to insecure deserialization, allowing attackers to execute arbitrary commands on the server. The vulnerability arises from the application's failure to securely handle serialized data, enabling attackers to supply malicious payloads that are deserialized and executed by the server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains an exploit for CVE-2024-1651 targeting a web application (likely a forum or CMS) running at http://telolet.htr/. The main exploit logic is in 'solve.py', which automates authentication using hardcoded admin credentials, crafts a serialized PHP payload to upload a webshell, and provides an interactive command execution interface if the upload is successful. The webshell is a simple PHP script that executes commands sent via HTTP POST. The 'heker' file is a Python one-liner that, when executed on the target, opens a reverse shell to 10.18.200.144:1337. The repository structure is minimal, with a README, the main exploit script, and a reverse shell helper. The exploit is operational and provides a working attack chain from authentication bypass to remote code execution.
This repository provides a working proof-of-concept exploit for CVE-2024-1651, an insecure object deserialization vulnerability that leads to remote code execution (RCE) in a web application. The main exploit script, 'exploit.py', is a Python program that automates the exploitation process. It requires valid credentials and a forum ID to authenticate to the target application. The script crafts a malicious serialized payload (using a Guzzle/FW1 gadget chain) and abuses the application's deserialization process to upload a PHP web shell to a predictable location on the server. Once the shell is uploaded, the script provides an interactive command interface, allowing the attacker to execute arbitrary commands on the compromised server via HTTP POST requests to the web shell. The repository contains three files: a LICENSE, a README.md describing the vulnerability and usage, and the main exploit script. The exploit is operational and demonstrates a full attack chain from authentication to remote code execution.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.