CVE-2008-0807
Title: Horde Groupware Webmail Edition
Proof Of Concept
No public PoC currently indexed for CVE-2008-0807.
Vulnerability Summary
CVE-2008-0807: lib/Driver/sql.php in Turba 2 (turba2) Contact Manager H3 2.1.x before 2.1.7 and 2.2.x before 2.2-RC3, as used in products such as Horde Groupware before 1.0.4 and Horde Groupware Webmail Edition before 1.0.5, does not properly check access rights, which allows remote authenticated users to modify address data via a modified object_id parameter to edit.php, as demonstrated by modifying a personal address book entry when there is write access to a shared address book.
Impacted Vendors
Reference Links
AV:N/AC:M/Au:S/C:P/I:P/A:N
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
CVE-2008-0807 Exploits & PoCs (Proof Of Concept)
No public PoCs found in our database for this CVE.
Vulnerability data updated via NVD.
Vulnerability data or affected products updated.
Vulnerability first announced in NVD.
Attack Vector Matrix
AV:N/AC:M/Au:S/C:P/I:P/A:N
Affected Stack
No specific products linked.