CVE-2008-0807
published 2008-02-19CVE-2008-0807: lib/Driver/sql.php in Turba 2 (turba2) Contact Manager H3 2.1.x before 2.1.7 and 2.2.x before 2.2-RC3, as used in products such as Horde Groupware before 1.0.4…
PriorityP424medium4.9CVSS 2.0
AVNACMAuSCPIPAN
EPSS
1.38%
68.8th percentile
lib/Driver/sql.php in Turba 2 (turba2) Contact Manager H3 2.1.x before 2.1.7 and 2.2.x before 2.2-RC3, as used in products such as Horde Groupware before 1.0.4 and Horde Groupware Webmail Edition before 1.0.5, does not properly check access rights, which allows remote authenticated users to modify address data via a modified object_id parameter to edit.php, as demonstrated by modifying a personal address book entry when there is write access to a shared address book.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| horde | groupware | — | — |
| horde | groupware_webmail_edition | — | — |
| horde | turba_contact_manager | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:N
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
turba: insufficient access checks
vendor_redhat·2008-02-04·CVSS 4.9
CVE-2008-0807 [MEDIUM] turba: insufficient access checks
turba: insufficient access checks
lib/Driver/sql.php in Turba 2 (turba2) Contact Manager H3 2.1.x before 2.1.7 and 2.2.x before 2.2-RC3, as used in products such as Horde Groupware before 1.0.4 and Horde Groupware Webmail Edition before 1.0.5, does not properly check access rights, which allows remote authenticated users to modify address data via a modified object_id parameter to edit.php, as demonstrated by modifying a personal address book entry when there is write access to a shared address book.
GHSA
GHSA-vv7v-g229-vwgh: lib/Driver/sql
ghsa_unreviewed·2022-05-01
CVE-2008-0807 [MEDIUM] GHSA-vv7v-g229-vwgh: lib/Driver/sql
lib/Driver/sql.php in Turba 2 (turba2) Contact Manager H3 2.1.x before 2.1.7 and 2.2.x before 2.2-RC3, as used in products such as Horde Groupware before 1.0.4 and Horde Groupware Webmail Edition before 1.0.5, does not properly check access rights, which allows remote authenticated users to modify address data via a modified object_id parameter to edit.php, as demonstrated by modifying a personal address book entry when there is write access to a shared address book.
No detection rules found.
No public exploits indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=464058http://lists.horde.org/archives/announce/2008/000378.htmlhttp://lists.horde.org/archives/announce/2008/000379.htmlhttp://lists.horde.org/archives/announce/2008/000380.htmlhttp://lists.horde.org/archives/announce/2008/000381.htmlhttp://secunia.com/advisories/28982http://secunia.com/advisories/29071http://secunia.com/advisories/29184http://secunia.com/advisories/29185http://secunia.com/advisories/29186http://www.debian.org/security/2008/dsa-1507http://www.securityfocus.com/bid/27844http://www.securitytracker.com/id?1019433http://www.vupen.com/english/advisories/2008/0593/referenceshttps://bugzilla.redhat.com/show_bug.cgi?id=432027https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00888.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-February/msg00927.htmlhttp://bugs.debian.org/cgi-bin/bugreport.cgi?bug=464058http://lists.horde.org/archives/announce/2008/000378.htmlhttp://lists.horde.org/archives/announce/2008/000379.htmlhttp://lists.horde.org/archives/announce/2008/000380.htmlhttp://lists.horde.org/archives/announce/2008/000381.htmlhttp://secunia.com/advisories/28982http://secunia.com/advisories/29071http://secunia.com/advisories/29184http://secunia.com/advisories/29185http://secunia.com/advisories/29186http://www.debian.org/security/2008/dsa-1507http://www.securityfocus.com/bid/27844http://www.securitytracker.com/id?1019433http://www.vupen.com/english/advisories/2008/0593/referenceshttps://bugzilla.redhat.com/show_bug.cgi?id=432027https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00888.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-February/msg00927.html
2008-02-19
Published