ZeroHour

CVE-2019-17199

PoC
CVSS 3.1
7.5 high
EPSS
10%p95
Published
()
Modified
Description

www/getfile.php in WPO WebPageTest 19.04 on Windows allows Directory Traversal (for reading arbitrary files) because of an unanchored regular expression, as demonstrated by the a.jpg\.. substring.

Vendors
webpagetest
Products
webpagetest
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.