CVE-2019-12161
17.05.2019, 19:29
WPO WebPageTest 19.04 allows SSRF because ValidateURL in www/runtest.php does not consider octal encoding of IP addresses (such as 0300.0250 as a replacement for 192.168).
Vendor | Product | Version |
---|---|---|
webpagetest | webpagetest | 19.04 |
𝑥
= Vulnerable software versions