CVE-2010-4608 describes an information disclosure vulnerability in Habari 0.6.5, allowing remote attackers to reveal the installation path through error messages generated by direct requests to header.php and comments_items.php in the system/admin/ directory. This vulnerability has a CVSS score of 5.0, indicating a medium severity with low attack complexity and no authentication required, potentially leading to a compromise of confidentiality. While no active exploitation is noted and community discussion is minimal, exploit code is publicly available via ExploitDB, though not in Metasploit or Nuclei.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.6.5CPE matchmatch criteria | cpe:2.3:a:habariproject:habari:0.6.5:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.