CVE-2019-17199

Publication date

2019-10-05 19:04:23

Family

mitre

State

PUBLISHED

Description

www/getfile.php in WPO WebPageTest 19.04 on Windows allows Directory Traversal (for reading arbitrary files) because of an unanchored regular expression, as demonstrated by the a.jpg.. substring.