PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Starting in version 1.7.7 and prior to version 2.0.3, an unauthenticated Local File Inclusion exists in the template-switching feature. If templateselection is enabled in the configuration, the server trusts the template cookie and includes the referenced PHP file. An attacker can read sensitive data or, if they manage to drop a PHP file elsewhere, gain remote code execution. The constructed path of the template file is checked for existence, then included. For PrivateBin project files this does not leak any secrets due to data files being created with PHP code that prevents execution, but if a configuration file without that line got created or the visitor figures out the relative path to a PHP script that directly performs an action without appropriate privilege checking, those might execute or leak information. The issue has been patched in version 2.0.3. As a workaround, set templateselection = false (which is the default) in cfg/conf.php or remove it entirely
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a single Python PoC script plus documentation/license files. The main file, `CVE-2025-64714-Poc.py`, targets CVE-2025-64714 in PrivateBin by abusing the `template` cookie to traverse out of the `tpl/` directory and force inclusion of arbitrary PHP files. The exploit supports three practical modes: (1) detection by probing `../cfg/conf`, (2) pure LFI/info-leak style inclusion of attacker-specified PHP files via `--template`, and (3) an RCE chain that invokes a pre-existing PHP webshell via LFI using `--upload-shell`, `--cmd`, or `--interactive`. The script uses Python `requests`, creates a session with a custom User-Agent, disables TLS verification by default, and sends GET requests with the malicious cookie and optional query parameters. The included payload is a simple PHP webshell that executes the `cmd` request parameter with `shell_exec()`. Importantly, the repository documentation repeatedly states that the vulnerability itself is only LFI; the script does not actually upload a shell or create a write primitive, despite the `--upload-shell` naming. Therefore the exploit is operational for detection/LFI and for command execution only when chained with a separate vulnerability or prior filesystem access. The repository structure is minimal: one Python exploit, one README with vulnerability analysis and usage examples, and standard ethical-use/license notices.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.