CVE-2012-10024 - CVE House
Back to Database
Status published High CVE-2012-10024

XBMC ≤ 11.0 Web Server Path Traversal

Vulnerability Description

XBMC version 11.0 contains a path traversal vulnerability in its embedded HTTP server. When accessed via HTTP Basic Authentication, the server fails to properly sanitize URI input, allowing authenticated users to request files outside the intended document root. An attacker can exploit this flaw to read arbitrary files from the host filesystem, including sensitive configuration or credential files.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-10024

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Lucas "acidgen" Lundgren

Affected Vendor

Affected Software

Media Center
Vulnerable Versions:
0

Timeline

Official Publish: August 5th, 2025
Last Modified: July 15th, 2026
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)