CVE-2012-10049
CRITICALWebPageTest <2.6 - RCE
Title source: llmDescription
WebPageTest version 2.6 and earlier contains an arbitrary file upload vulnerability in the resultimage.php script. The application fails to validate or sanitize user-supplied input before saving uploaded files to a publicly accessible directory. This flaw allows remote attackers to upload and execute arbitrary PHP code, resulting in full remote code execution under the web server context.
Exploits (3)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubywebappsphp
https://www.exploit-db.com/exploits/20173
metasploit
WORKING POC
EXCELLENT
by dun, sinn3r · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/webpagetest_upload_exec.rb
References (6)
Scores
CVSS v4
9.3
EPSS
0.6972
EPSS Percentile
98.7%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-434
Status
published
Products (1)
WPO Foundation/WebPageTest
< 2.6
Published
Aug 08, 2025
Tracked Since
Feb 18, 2026