CVE-2008-0807
Summary
| CVE | CVE-2008-0807 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-02-19 01:00:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | lib/Driver/sql.php in Turba 2 (turba2) Contact Manager H3 2.1.x before 2.1.7 and 2.2.x before 2.2-RC3, as used in products such as Horde Groupware before 1.0.4 and Horde Groupware Webmail Edition before 1.0.5, does not properly check access rights, which allows remote authenticated users to modify address data via a modified object_id parameter to edit.php, as demonstrated by modifying a personal address book entry when there is write access to a shared address book. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:S/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 4.0 | All | All | All |
| Operating System | Debian | Debian Linux | 4.0 | All | alpha | All |
| Operating System | Debian | Debian Linux | 4.0 | All | amd64 | All |
| Operating System | Debian | Debian Linux | 4.0 | All | arm | All |
| Operating System | Debian | Debian Linux | 4.0 | All | hppa | All |
| Operating System | Debian | Debian Linux | 4.0 | All | ia-32 | All |
| Operating System | Debian | Debian Linux | 4.0 | All | ia-64 | All |
| Operating System | Debian | Debian Linux | 4.0 | All | m68k | All |
| Operating System | Debian | Debian Linux | 4.0 | All | mips | All |
| Operating System | Debian | Debian Linux | 4.0 | All | mipsel | All |
| Operating System | Debian | Debian Linux | 4.0 | All | powerpc | All |
| Operating System | Debian | Debian Linux | 4.0 | All | s-390 | All |
| Operating System | Debian | Debian Linux | 4.0 | All | sparc | All |
| Application | Horde | Groupware | 1.0.3 | All | All | All |
| Application | Horde | Groupware Webmail Edition | 1.0.4 | All | All | All |
| Application | Horde | Turba Contact Manager | 2.1.6 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Fedora update for horde - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Horde Groupware Discloses Address Book Contacts to Remote Users - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| [announce] Horde Groupware 1.0.4 (final) | af854a3a-2127-422b-91ae-364da2661108 | lists.horde.org | Patch |
| Debian update for turba2 - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| #464058 - turba2: Access rights not checked properly - Debian Bug report logs | af854a3a-2127-422b-91ae-364da2661108 | bugs.debian.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| [announce] Horde Groupware Webmail Edition 1.0.5 (final) | af854a3a-2127-422b-91ae-364da2661108 | lists.horde.org | Patch |
| Fedora update for imp - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [announce] Turba H3 (2.1.7) (final) | af854a3a-2127-422b-91ae-364da2661108 | lists.horde.org | Patch |
| [SECURITY] Fedora 8 Update: turba-2.1.7-1.fc8 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| [SECURITY] Fedora 7 Update: turba-2.1.7-1.fc7 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Debian -- Security Information -- DSA-1507-1 turba2 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| [announce] Turba H3 (2.2-RC3) | af854a3a-2127-422b-91ae-364da2661108 | lists.horde.org | Patch |
| Bug 432027 – CVE-2008-0807 turba: insufficient access checks | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| Multiple Horde Products Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| Fedora update for turba - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Multiple Horde Products Security Bypass - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.