Show plain JSON{"cve": {"data_type": "CVE", "references": {"reference_data": [{"url": "http://lists.horde.org/archives/announce/2008/000380.html", "name": "[announce] 20080215 Horde Groupware 1.0.4 (final)", "tags": ["Patch"], "refsource": "MLIST"}, {"url": "http://lists.horde.org/archives/announce/2008/000381.html", "name": "[announce] 20080215 Horde Groupware Webmail Edition 1.0.5 (final)", "tags": ["Patch"], "refsource": "MLIST"}, {"url": "http://lists.horde.org/archives/announce/2008/000379.html", "name": "[announce] 20080215 Turba H3 (2.2-RC3)", "tags": ["Patch"], "refsource": "MLIST"}, {"url": "http://lists.horde.org/archives/announce/2008/000378.html", "name": "[announce] 20080215 Turba H3 (2.1.7) (final)", "tags": ["Patch"], "refsource": "MLIST"}, {"url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=464058", "name": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=464058", "tags": [], "refsource": "CONFIRM"}, {"url": "http://www.securityfocus.com/bid/27844", "name": "27844", "tags": ["Patch"], "refsource": "BID"}, {"url": "http://secunia.com/advisories/28982", "name": "28982", "tags": ["Vendor Advisory"], "refsource": "SECUNIA"}, {"url": "http://www.debian.org/security/2008/dsa-1507", "name": "DSA-1507", "tags": [], "refsource": "DEBIAN"}, {"url": "http://www.securitytracker.com/id?1019433", "name": "1019433", "tags": [], "refsource": "SECTRACK"}, {"url": "http://secunia.com/advisories/29071", "name": "29071", "tags": [], "refsource": "SECUNIA"}, {"url": "https://bugzilla.redhat.com/show_bug.cgi?id=432027", "name": "https://bugzilla.redhat.com/show_bug.cgi?id=432027", "tags": [], "refsource": "CONFIRM"}, {"url": "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00888.html", "name": "FEDORA-2008-2040", "tags": [], "refsource": "FEDORA"}, {"url": "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00927.html", "name": "FEDORA-2008-2087", "tags": [], "refsource": "FEDORA"}, {"url": "http://secunia.com/advisories/29184", "name": "29184", "tags": [], "refsource": "SECUNIA"}, {"url": "http://secunia.com/advisories/29185", "name": "29185", "tags": [], "refsource": "SECUNIA"}, {"url": "http://secunia.com/advisories/29186", "name": "29186", "tags": [], "refsource": "SECUNIA"}, {"url": "http://www.vupen.com/english/advisories/2008/0593/references", "name": "ADV-2008-0593", "tags": [], "refsource": "VUPEN"}]}, "data_format": "MITRE", "description": {"description_data": [{"lang": "en", "value": "lib/Driver/sql.php in Turba 2 (turba2) Contact Manager H3 2.1.x before 2.1.7 and 2.2.x before 2.2-RC3, as used in products such as Horde Groupware before 1.0.4 and Horde Groupware Webmail Edition before 1.0.5, does not properly check access rights, which allows remote authenticated users to modify address data via a modified object_id parameter to edit.php, as demonstrated by modifying a personal address book entry when there is write access to a shared address book."}]}, "problemtype": {"problemtype_data": [{"description": [{"lang": "en", "value": "CWE-264"}]}]}, "data_version": "4.0", "CVE_data_meta": {"ID": "CVE-2008-0807", "ASSIGNER": "cve@mitre.org"}}, "impact": {"baseMetricV2": {"cvssV2": {"version": "2.0", "baseScore": 4.9, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:S/C:P/I:P/A:N", "authentication": "SINGLE", "integrityImpact": "PARTIAL", "accessComplexity": "MEDIUM", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "severity": "MEDIUM", "impactScore": 4.9, "obtainAllPrivilege": false, "exploitabilityScore": 6.8, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}}, "publishedDate": "2008-02-19T01:00Z", "configurations": {"nodes": [{"children": [{"children": [], "operator": "OR", "cpe_match": [{"cpe23Uri": "cpe:2.3:o:debian:debian_linux:4.0:*:ia-64:*:*:*:*:*", "cpe_name": [], "vulnerable": false}, {"cpe23Uri": "cpe:2.3:o:debian:debian_linux:4.0:*:m68k:*:*:*:*:*", "cpe_name": [], "vulnerable": false}, {"cpe23Uri": "cpe:2.3:o:debian:debian_linux:4.0:*:arm:*:*:*:*:*", "cpe_name": [], "vulnerable": false}, {"cpe23Uri": "cpe:2.3:o:debian:debian_linux:4.0:*:hppa:*:*:*:*:*", "cpe_name": [], "vulnerable": false}, {"cpe23Uri": "cpe:2.3:o:debian:debian_linux:4.0:*:ia-32:*:*:*:*:*", "cpe_name": [], "vulnerable": false}, {"cpe23Uri": "cpe:2.3:o:debian:debian_linux:4.0:*:sparc:*:*:*:*:*", "cpe_name": [], "vulnerable": false}, {"cpe23Uri": "cpe:2.3:o:debian:debian_linux:4.0:*:alpha:*:*:*:*:*", "cpe_name": [], "vulnerable": false}, {"cpe23Uri": "cpe:2.3:o:debian:debian_linux:4.0:*:amd64:*:*:*:*:*", "cpe_name": [], "vulnerable": false}, {"cpe23Uri": "cpe:2.3:o:debian:debian_linux:4.0:*:powerpc:*:*:*:*:*", "cpe_name": [], "vulnerable": false}, {"cpe23Uri": "cpe:2.3:o:debian:debian_linux:4.0:*:s-390:*:*:*:*:*", "cpe_name": [], "vulnerable": false}, {"cpe23Uri": "cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": false}, {"cpe23Uri": "cpe:2.3:o:debian:debian_linux:4.0:*:mipsel:*:*:*:*:*", "cpe_name": [], "vulnerable": false}, {"cpe23Uri": "cpe:2.3:o:debian:debian_linux:4.0:*:mips:*:*:*:*:*", "cpe_name": [], "vulnerable": false}]}, {"children": [], "operator": "OR", "cpe_match": [{"cpe23Uri": "cpe:2.3:a:horde:groupware:1.0.3:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}, {"cpe23Uri": "cpe:2.3:a:horde:groupware_webmail_edition:1.0.4:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}, {"cpe23Uri": "cpe:2.3:a:horde:turba_contact_manager:2.1.6:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}]}], "operator": "AND", "cpe_match": []}], "CVE_data_version": "4.0"}, "lastModifiedDate": "2011-03-08T03:05Z"}