| [Japanese] | 
| JVNDB-2008-000046 | 
| La!cooda WIZ and LacoodaST vulnerable to cross-site request forgery | 
|
| 
 
La!cooda WIZ and LacoodaST contain a cross-site request forgery vulnerability. 
 La!cooda WIZ from System Consultants Co., Ltd. and LacoodaST from SpaceTag, Inc. are groupware providing schedule and task managements, etc. La!cooda WIZ and LacoodaST contain a cross-site request forgery vulnerability.
 
 Hirotaka Katagiri reported this vulnerability to IPA.
 JPCERT/CC coordinated with the vendors under Information Security Early Warning Partnership.
 | 
|
| 
 
  CVSS V2 Severity:Base Metrics 2.6 (Low) [IPA Score]
 
    Access Vector: NetworkAccess Complexity: HighAuthentication: NoneConfidentiality Impact: NoneIntegrity Impact: PartialAvailability Impact: None 
  
 | 
|
| 
 
	
 | 
| 
 
	System Consultants Co.,Ltd.
	
		SPACETAG INC.La!coodaWIZ 1.4.0 and earlier 
		LacoodaST 2.1.3 and earlier | 
| 
 
	
 | 
|
| 
 
Password or other configurations may be changed if the logged in user views a malicious web page.
 | 
|
| 
 
[Update the Software]Apply the latest updates provided by the vendors.
 For more information, refer to the vendors' websites.
 | 
|
| 
 
	System Consultants Co.,Ltd.
	
	SPACETAG INC.
	
 | 
|
| 
 
	Cross-Site Request Forgery(CWE-352) [IPA Evaluation] | 
|
| 
 
	CVE-2008-3736  | 
|
| 
 
	JVN : JVN#83428818 National Vulnerability Database (NVD) : CVE-2008-3736 Secunia Advisory : SA31582 Secunia Advisory : SA31574 SecurityFocus : 30791 ISS X-Force Database : 44592 JVN iPedia (Japanese) : JVNDB-2008-000046  | 
|
| 
 
	[2008/09/02]Web page published
 
 |