PT-2008-2425 · Horde · Turba 2+2

Tomas Hoger

·

Published

2008-02-19

·

Updated

2011-03-08

·

CVE-2008-0807

CVSS v2.0

4.9

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Turba 2 (turba2) Contact Manager H3 versions 2.1.x through 2.1.6 Turba 2 (turba2) Contact Manager H3 versions 2.2.x through 2.2-RC2 Horde Groupware versions prior to 1.0.4 Horde Groupware Webmail Edition versions prior to 1.0.5
Description The issue allows remote authenticated users to modify address data by exploiting improper access rights checking. This can be achieved by modifying the object id parameter in the edit.php endpoint. For example, a user with write access to a shared address book can modify a personal address book entry.
Recommendations For Turba 2 (turba2) Contact Manager H3 versions 2.1.x, update to version 2.1.7 or later. For Turba 2 (turba2) Contact Manager H3 versions 2.2.x, update to version 2.2-RC3 or later. For Horde Groupware, update to version 1.0.4 or later. For Horde Groupware Webmail Edition, update to version 1.0.5 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-0807
DSA-1507-1

Affected Products

Horde Groupware
Horde Groupware Webmail Edition
Turba 2