[Japanese]
|
JVNDB-2008-000049
|
Vulnerability in La!cooda WIZ and LacoodaST allowing an arbitrary PHP script execution
|
La!cooda WIZ and LacoodaST contain a vulnerability which may allow a malicious user to execute an arbitrary PHP script on the server.
La!cooda WIZ from System Consultants Co., Ltd. and LacoodaST from SpaceTag, Inc. are groupware providing schedule and task managements, etc. La!cooda WIZ and LacoodaST contain a vulnerability which may allow a malicious user to execute an arbitrary PHP script on the server.
Hirotaka Katagiri reported this vulnerability to IPA.
JPCERT/CC coordinated with the vendors under Information Security Early Warning Partnership.
|
CVSS V2 Severity: Base Metrics 6.5 (Medium) [IPA Score]
- Access Vector: Network
- Access Complexity: Low
- Authentication: Single Instance
- Confidentiality Impact: Partial
- Integrity Impact: Partial
- Availability Impact: Partial
|
|
System Consultants Co.,Ltd.
- La!coodaWIZ 1.4.0 and earlier
SPACETAG INC.
- LacoodaST 2.1.3 and earlier
|
|
If an arbitrary PHP script is executed, files on the server could be deleted or disclosed.
|
[Update the Software]
Apply the latest updates provided by the vendors.
For more information, refer to the vendors' websites.
|
System Consultants Co.,Ltd.
SPACETAG INC.
|
- Code Injection(CWE-94) [IPA Evaluation]
|
- CVE-2008-3737
|
- JVN : JVN#53886050
- National Vulnerability Database (NVD) : CVE-2008-3737
- Secunia Advisory : SA31582
- Secunia Advisory : SA31574
- SecurityFocus : 30791
- ISS X-Force Database : 44594
- JVN iPedia (Japanese) : JVNDB-2008-000049
|
- [2008/09/02]
Web page published
|