CVE-2012-10049
WebPageTest <2.6 - RCE
Title source: llmDescription
WebPageTest version 2.6 and earlier contains an arbitrary file upload vulnerability in the resultimage.php script. The application fails to validate or sanitize user-supplied input before saving uploaded files to a publicly accessible directory. This flaw allows remote attackers to upload and execute arbitrary PHP code, resulting in full remote code execution under the web server context.
Exploits (3)
metasploit
WORKING POC
EXCELLENT
by dun, sinn3r · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/webpagetest_upload_exec.rb
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubywebappsphp
https://www.exploit-db.com/exploits/20173
References (6)
Scores
EPSS
0.6653
EPSS Percentile
98.5%
Classification
CWE
CWE-434
Status
draft
Timeline
Published
Aug 08, 2025
Tracked Since
Feb 18, 2026