XBMC ≤ 11.0 Web Server Path Traversal
Vulnerability Description
XBMC version 11.0 contains a path traversal vulnerability in its embedded HTTP server. When accessed via HTTP Basic Authentication, the server fails to properly sanitize URI input, allowing authenticated users to request files outside the intended document root. An attacker can exploit this flaw to read arbitrary files from the host filesystem, including sensitive configuration or credential files.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-10024
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Lucas "acidgen" Lundgren
References
- https://www.ioactive.com/wp-content/uploads/pdfs/Security_Advisory_XBMC.pdf
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/auxiliary/gather/xbmc_traversal.rb
- https://github.com/xbmc/xbmc/commit/bdff099c024521941cb0956fe01d99ab52a65335
- https://github.com/xbmc/xbmc
- https://www.vulncheck.com/advisories/xbmc-web-server-path-traversal
Affected Vendor
XBMC
View all reports →