CVE-2012-10024
XBMC version 11.0 contains a path traversal vulnerability in its embedded HTTP server. When accessed via HTTP Basic Authentication, the server fails to properly sanitize URI input, allowing authenticated users to request files outside the intended document root. An attacker can exploit this flaw to read arbitrary files from the host filesystem, including sensitive configuration or credential files.
Published:Aug 5, 2025
Last Modified:Jul 15, 2026
EPS:Aug 5, 2025
EPSS Score:0.00851
CVSS Score:7.1
Affected Products
Vendor
Product
Action
Vendor
Uberrider
Product
Mediacenter
Uberrider
Mediacenter
Vendor
Xbmc
Product
Xbmc
Xbmc
Xbmc
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
