---
title: CVE-2012-10024
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2012-10024
---

# CVE-2012-10024

Publication date 5 August 2025

Last updated 17 September 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

XBMC version 11.0 contains a path traversal vulnerability in its embedded
HTTP server. When accessed via HTTP Basic Authentication, the server fails
to properly sanitize URI input, allowing authenticated users to request
files outside the intended document root. An attacker can exploit this flaw
to read arbitrary files from the host filesystem, including sensitive
configuration or credential files.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-10024)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2012-10024)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2012-10024)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2012-10024)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2012-10024>
* <https://github.com/xbmc/xbmc>
* <https://github.com/xbmc/xbmc/commit/bdff099c024521941cb0956fe01d99ab52a65335>
* <https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/auxiliary/gather/xbmc_traversal.rb>
* <https://www.ioactive.com/wp-content/uploads/pdfs/Security_Advisory_XBMC.pdf>
* <https://www.vulncheck.com/advisories/xbmc-web-server-path-traversal>
