Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2012-10024

39
FAUCET Score

CVE-2012-10024 describes a path traversal vulnerability in the embedded HTTP server of XBMC version 11, including nightly builds up to 2012-11-04. This flaw allows authenticated users, via HTTP Basic Authentication, to bypass URI sanitization and read arbitrary files from the host filesystem. Rated with a CVSS score of 7.1 (HIGH), this vulnerability has a low attack complexity and can lead to the disclosure of sensitive configuration or credential files. While not listed in CISA's KEV catalog, a Metasploit module exists for exploitation, and it has garnered significant community discussion with 20 mentions.

Impacted Technologies

VendorProductVersion(s)CPE
XBMCMedia Center
>= 0, <= 11.0CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 4.0

7.1HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.86%
Probability of exploitation in next 30 days
EPSS Percentile
54.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Metasploit: XBMC Web Server Directory Traversal · Nov 4, 2012
This CVE's current EPSS score of 0.0086 is in the 49th percentile among its peer group of 17,829 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / xbmc/xbmc
github.com / xbmc/xbmc/commit/bdff099c024521941cb0956fe01d99ab52a65335
raw.githubusercontent.com / rapid7/metasploit-framework/master/modules/auxiliary/gather/xbmc_traversal.rb
ioactive.com / wp-content/uploads/pdfs/Security_Advisory_XBMC.pdf
vulncheck.com / advisories/xbmc-web-server-path-traversal