Lucene search

K

Webpagetest Security Vulnerabilities

cve
cve

CVE-2017-6396

An issue was discovered in WPO-Foundation WebPageTest 3.0. The vulnerability exists due to insufficient filtration of user-supplied data passed to the "webpagetest-master/www/compare-cf.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable ...

6.1CVSS

6.3AI Score

0.001EPSS

2017-03-02 06:59 AM
22
cve
cve

CVE-2017-6533

A Cross-Site Scripting (XSS) issue was discovered in webpagetest 3.0. The vulnerability exists due to insufficient filtration of user-supplied data (benchmark) passed to the webpagetest-master/www/benchmarks/view.php URL. An attacker could execute arbitrary HTML and script code in a browser in the ...

6.1CVSS

5.8AI Score

0.001EPSS

2017-03-08 08:59 AM
24
cve
cve

CVE-2017-6534

A Cross-Site Scripting (XSS) issue was discovered in webpagetest 3.0. The vulnerability exists due to insufficient filtration of user-supplied data (pssid) passed to the webpagetest-master/www/pss.php URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the v...

6.1CVSS

5.8AI Score

0.001EPSS

2017-03-08 08:59 AM
20
cve
cve

CVE-2017-6535

Multiple Cross-Site Scripting (XSS) issues were discovered in webpagetest 3.0. The vulnerabilities exist due to insufficient filtration of user-supplied data (benchmark, url) passed to the webpagetest-master/www/benchmarks/trendurl.php URL. An attacker could execute arbitrary HTML and script code i...

6.1CVSS

6AI Score

0.001EPSS

2017-03-08 08:59 AM
18
cve
cve

CVE-2017-6536

Multiple Cross-Site Scripting (XSS) issues were discovered in webpagetest 3.0. The vulnerabilities exist due to insufficient filtration of user-supplied data (url, pssid) passed to the webpagetest-master/www/weblite.php URL. An attacker could execute arbitrary HTML and script code in a browser in t...

6.1CVSS

6AI Score

0.001EPSS

2017-03-08 08:59 AM
22
cve
cve

CVE-2017-6537

A Cross-Site Scripting (XSS) issue was discovered in webpagetest 3.0. The vulnerability exists due to insufficient filtration of user-supplied data (bgcolor) passed to the webpagetest-master/www/video/view.php URL. An attacker could execute arbitrary HTML and script code in a browser in the context...

6.1CVSS

5.8AI Score

0.001EPSS

2017-03-08 08:59 AM
22
cve
cve

CVE-2017-6538

A Cross-Site Scripting (XSS) issue was discovered in webpagetest 3.0. The vulnerability exists due to insufficient filtration of user-supplied data (video) passed to the webpagetest-master/www/speedindex/index.php URL. An attacker could execute arbitrary HTML and script code in a browser in the con...

6.1CVSS

5.8AI Score

0.001EPSS

2017-03-08 08:59 AM
24
cve
cve

CVE-2017-6539

Multiple Cross-Site Scripting (XSS) issues were discovered in webpagetest 3.0. The vulnerabilities exist due to insufficient filtration of user-supplied data (benchmark, time) passed to the webpagetest-master/www/benchmarks/delta.php URL. An attacker could execute arbitrary HTML and script code in ...

6.1CVSS

6AI Score

0.001EPSS

2017-03-08 08:59 AM
24
cve
cve

CVE-2017-6540

Multiple Cross-Site Scripting (XSS) issues were discovered in webpagetest 3.0. The vulnerabilities exist due to insufficient filtration of user-supplied data (configs) passed to the webpagetest-master/www/benchmarks/compare.php URL. An attacker could execute arbitrary HTML and script code in a brow...

6.1CVSS

6AI Score

0.001EPSS

2017-03-08 08:59 AM
19
cve
cve

CVE-2017-6541

Multiple Cross-Site Scripting (XSS) issues were discovered in webpagetest 3.0. The vulnerabilities exist due to insufficient filtration of user-supplied data (benchmark, time) passed to the webpagetest-master/www/benchmarks/viewtest.php URL. An attacker could execute arbitrary HTML and script code ...

6.1CVSS

6AI Score

0.001EPSS

2017-03-08 08:59 AM
22
cve
cve

CVE-2019-12161

WPO WebPageTest 19.04 allows SSRF because ValidateURL in www/runtest.php does not consider octal encoding of IP addresses (such as 0300.0250 as a replacement for 192.168).

8.8CVSS

8.6AI Score

0.001EPSS

2019-05-17 07:29 PM
20
cve
cve

CVE-2019-17199

www/getfile.php in WPO WebPageTest 19.04 on Windows allows Directory Traversal (for reading arbitrary files) because of an unanchored regular expression, as demonstrated by the a.jpg.. substring.

7.5CVSS

7.5AI Score

0.006EPSS

2019-10-05 08:15 PM
95