>> Horde Products Security Bypass and Information Disclosure Issue
Title : Horde Products Security Bypass and Information Disclosure Issue VUPEN ID : VUPEN/ADV-2008-0593 CVE ID : CVE-2008-0807
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-02-19
Technical Description
A vulnerability has been identified in Horde Groupware and Turba, which could be exploited by attackers to bypass security restrictions and disclose sensitive information. This issue is caused by missing access checks, which could be exploited to gain unauthorized access to contacts in the same SQL table, if the unique key of another user's contact can be guessed.
Upgrade to Horde Groupware version 1.0.4, Horde Groupware Webmail version 1.0.5 and Turba Contact Manager version 2.1.7 : http://www.horde.org/download/ References