CVE-2012-10049

WebPageTest <2.6 - RCE

Title source: llm

Description

WebPageTest version 2.6 and earlier contains an arbitrary file upload vulnerability in the resultimage.php script. The application fails to validate or sanitize user-supplied input before saving uploaded files to a publicly accessible directory. This flaw allows remote attackers to upload and execute arbitrary PHP code, resulting in full remote code execution under the web server context.

Exploits (3)

exploitdb WORKING POC VERIFIED
by dun · textwebappsphp
https://www.exploit-db.com/exploits/19790
metasploit WORKING POC EXCELLENT
by dun, sinn3r · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/webpagetest_upload_exec.rb
exploitdb WORKING POC VERIFIED
by Metasploit · rubywebappsphp
https://www.exploit-db.com/exploits/20173

Scores

EPSS 0.6653
EPSS Percentile 98.5%

Classification

CWE
CWE-434
Status draft

Timeline

Published Aug 08, 2025
Tracked Since Feb 18, 2026