CVE-2008-3717
Harmoni before 1.6.0 does not require administrative privileges to list (1) user names or (2) asset ids, which allows remote attackers to obtain sensitive information.
Date published : 2008-08-19
http://www.securityfocus.com/bid/30706
http://sourceforge.net/project/shownotes.php?release_id=619864