Privatebin

Privatebin

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 13.11.2025 15:16:55
  • Zuletzt bearbeitet 14.11.2025 16:42:03

PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Starting in version 1.7.7 and prior to version 2.0.3, an unauthenticated Local File Inclusion exists in the template-switching feature. If `templateselection` is ena...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 13.11.2025 01:50:31
  • Zuletzt bearbeitet 25.11.2025 17:37:36

PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Starting in version 1.7.7 and prior to version 2.0.3, dragging a file whose filename contains HTML is reflected verbatim into the page via the drag-and-drop helper, ...

  • EPSS 0.02%
  • Veröffentlicht 28.10.2025 20:47:50
  • Zuletzt bearbeitet 30.10.2025 15:05:32

PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Versions 1.7.7 through 2.0.1 allow persistent HTML injection via the unsanitized attachment filename (attachment_name) when attachments are enabled. An attacker can ...

  • EPSS 0.11%
  • Veröffentlicht 09.07.2024 19:15:13
  • Zuletzt bearbeitet 21.11.2024 09:28:31

PrivateBin is an online pastebin where the server has zero knowledge of pasted data. In v1.5, PrivateBin introduced the YOURLS server-side proxy. The idea was to allow using the YOURLs URL shortener without running the YOURLs instance without authent...

Exploit
  • EPSS 0.5%
  • Veröffentlicht 11.04.2022 21:15:08
  • Zuletzt bearbeitet 21.11.2024 06:51:11

PrivateBin is minimalist, open source online pastebin clone where the server has zero knowledge of pasted data. In PrivateBin < v1.4.0 a cross-site scripting (XSS) vulnerability was found. The vulnerability is present in all versions from v0.21 of th...

Exploit
  • EPSS 0.45%
  • Veröffentlicht 23.01.2020 02:15:13
  • Zuletzt bearbeitet 21.11.2024 05:33:42

In PrivateBin versions 1.2.0 before 1.2.2, and 1.3.0 before 1.3.2, a persistent XSS attack is possible. Under certain conditions, a user provided attachment file name can inject HTML leading to a persistent Cross-site scripting (XSS) vulnerability. T...