CVE-2008-0807
lib/Driver/sql.php in Turba 2 (turba2) Contact Manager H3 2.1.x before 2.1.7 and 2.2.x before 2.2-RC3, as used in products such as Horde Groupware before 1.0.4 and Horde Groupware Webmail Edition before 1.0.5, does not properly check access rights,…
Does this matter?
Lower severity and a low EPSS score (1.38%). Track it; it rarely justifies an emergency change on its own.
Description
lib/Driver/sql.php in Turba 2 (turba2) Contact Manager H3 2.1.x before 2.1.7 and 2.2.x before 2.2-RC3, as used in products such as Horde Groupware before 1.0.4 and Horde Groupware Webmail Edition before 1.0.5, does not properly check access rights, which allows remote authenticated users to modify address data via a modified object_id parameter to edit.php, as demonstrated by modifying a personal address book entry when there is write access to a shared address book.
- CVSS 2.0
- 4.9 MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:N
- EPSS
- 1.38% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- horde/groupware · horde/groupware webmail edition · horde/turba contact manager
- Source
- cve@mitre.org
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=464058
- http://lists.horde.org/archives/announce/2008/000378.htmlPatch
- http://lists.horde.org/archives/announce/2008/000379.htmlPatch
- http://lists.horde.org/archives/announce/2008/000380.htmlPatch
- http://lists.horde.org/archives/announce/2008/000381.htmlPatch
- http://secunia.com/advisories/28982Vendor Advisory
- http://secunia.com/advisories/29071
- http://secunia.com/advisories/29184
- http://secunia.com/advisories/29185
- http://secunia.com/advisories/29186
- http://www.debian.org/security/2008/dsa-1507
- http://www.securityfocus.com/bid/27844Patch
- http://www.securitytracker.com/id?1019433
- http://www.vupen.com/english/advisories/2008/0593/references
- https://bugzilla.redhat.com/show_bug.cgi?id=432027
- https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00888.html
- https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00927.html
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=464058
- http://lists.horde.org/archives/announce/2008/000378.htmlPatch
- http://lists.horde.org/archives/announce/2008/000379.htmlPatch
- http://lists.horde.org/archives/announce/2008/000380.htmlPatch
- http://lists.horde.org/archives/announce/2008/000381.htmlPatch
- http://secunia.com/advisories/28982Vendor Advisory
- http://secunia.com/advisories/29071
- http://secunia.com/advisories/29184
- http://secunia.com/advisories/29185
- http://secunia.com/advisories/29186
- http://www.debian.org/security/2008/dsa-1507
- http://www.securityfocus.com/bid/27844Patch
- http://www.securitytracker.com/id?1019433
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.