CVE-2012-10024 describes a path traversal vulnerability in the embedded HTTP server of XBMC version 11, including nightly builds up to 2012-11-04. This flaw allows authenticated users, via HTTP Basic Authentication, to bypass URI sanitization and read arbitrary files from the host filesystem. Rated with a CVSS score of 7.1 (HIGH), this vulnerability has a low attack complexity and can lead to the disclosure of sensitive configuration or credential files. While not listed in CISA's KEV catalog, a Metasploit module exists for exploitation, and it has garnered significant community discussion with 20 mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| XBMC | Media Center | >= 0, <= 11.0CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.