CVE-2008-4601
Habari Cms - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in the login feature in Habari CMS 0.5.1 allows remote attackers to inject arbitrary web script or HTML via the habari_username parameter.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by faithlove · textwebappsphp
https://www.exploit-db.com/exploits/32492
Scores
EPSS
0.0250
EPSS Percentile
85.1%
Classification
CWE
CWE-79
Status
published
Affected Products (2)
habari/cms
n/a/n/a
Timeline
Published
Oct 18, 2008
Tracked Since
Feb 18, 2026