CVE-2012-10024

HIGH

XBMC/Media Center < 11.0 - Authenticated Path Traversal via HTTP Server URI

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-10024. PoCs published by sinn3r, s yaws_traversal exploit as a skeleton, acidgen, ,, hostess, including Metasploit module auxiliary/gather/xbmc_traversal.

AI-analyzed exploit summary This Metasploit module exploits a directory traversal vulnerability in XBMC Web Server (CVE-2012-10024) to retrieve arbitrary files. It uses HTTP GET requests with path traversal sequences and optional authentication.

Description

XBMC version 11.0 contains a path traversal vulnerability in its embedded HTTP server. When accessed via HTTP Basic Authentication, the server fails to properly sanitize URI input, allowing authenticated users to request files outside the intended document root. An attacker can exploit this flaw to read arbitrary files from the host filesystem, including sensitive configuration or credential files.

Exploits (1)

metasploit WORKING POC
by sinn3r, s yaws_traversal exploit as a skeleton, acidgen, ,, hostess · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/xbmc_traversal.rb

This Metasploit module exploits a directory traversal vulnerability in XBMC Web Server (CVE-2012-10024) to retrieve arbitrary files. It uses HTTP GET requests with path traversal sequences and optional authentication.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: XBMC Web Server (versions up to 2012-11-04 nightly build)
Auth required
Prerequisites: Network access to XBMC Web Server · Valid credentials if authentication is enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v4 7.1
EPSS 0.0106
EPSS Percentile 60.1%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
XBMC/Media Center < 11.0
Published Aug 05, 2025
Tracked Since Feb 18, 2026