Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q67w-8wvh-9fwh

Опубликовано: 08 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.3

Описание

WebPageTest version 2.6 and earlier contains an arbitrary file upload vulnerability in the resultimage.php script. The application fails to validate or sanitize user-supplied input before saving uploaded files to a publicly accessible directory. This flaw allows remote attackers to upload and execute arbitrary PHP code, resulting in full remote code execution under the web server context.

WebPageTest version 2.6 and earlier contains an arbitrary file upload vulnerability in the resultimage.php script. The application fails to validate or sanitize user-supplied input before saving uploaded files to a publicly accessible directory. This flaw allows remote attackers to upload and execute arbitrary PHP code, resulting in full remote code execution under the web server context.

EPSS

Процентиль: 98%
0.66533
Средний

9.3 Critical

CVSS4

Дефекты

CWE-434

Связанные уязвимости

nvd
6 месяцев назад

WebPageTest version 2.6 and earlier contains an arbitrary file upload vulnerability in the resultimage.php script. The application fails to validate or sanitize user-supplied input before saving uploaded files to a publicly accessible directory. This flaw allows remote attackers to upload and execute arbitrary PHP code, resulting in full remote code execution under the web server context.

EPSS

Процентиль: 98%
0.66533
Средний

9.3 Critical

CVSS4

Дефекты

CWE-434