{"api_version":"1","generated_at":"2026-07-23T09:36:09+00:00","cve":"CVE-2008-3737","urls":{"html":"https://cve.report/CVE-2008-3737","api":"https://cve.report/api/cve/CVE-2008-3737.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-3737","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-3737"},"summary":{"title":"CVE-2008-3737","description":"Unspecified vulnerability in (1) System Consultants La!Cooda WIZ 1.4.0 and earlier and (2) SpaceTag LacoodaST 2.1.3 and earlier allows remote attackers to execute arbitrary PHP scripts, and delete files, read files, and possibly have unknown other impact.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-08-27 20:41:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-94","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://wiz.syscon.co.jp/Details.htm","name":"http://wiz.syscon.co.jp/Details.htm","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://secunia.com/advisories/31574","name":"http://secunia.com/advisories/31574","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"La!cooda WIZ Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://jvn.jp/en/jp/JVN53886050/index.html","name":"http://jvn.jp/en/jp/JVN53886050/index.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"JVN#53886050 Vulnerability in La!cooda WIZ and LacoodaST allowing an arbitrary PHP script execution","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44594","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44594","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/31582","name":"http://secunia.com/advisories/31582","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"LacoodaST Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/30791","name":"http://www.securityfocus.com/bid/30791","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"LacoodaST and La!cooda WIZ Multiple Remote Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-3737","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-3737","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"3737","vulnerable":"1","versionEndIncluding":"2.1.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"spacetag","cpe5":"lacoodast","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3737","vulnerable":"1","versionEndIncluding":"1.4.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"system_consultants","cpe5":"la_cooda_wiz","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T09:52:59.265Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"JVN#53886050","tags":["third-party-advisory","x_refsource_JVN","x_transferred"],"url":"http://jvn.jp/en/jp/JVN53886050/index.html"},{"name":"lacooda-unspecified-code-execution(44594)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44594"},{"name":"30791","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/30791"},{"name":"31574","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/31574"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://wiz.syscon.co.jp/Details.htm"},{"name":"31582","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/31582"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-08-21T00:00:00.000Z","descriptions":[{"lang":"en","value":"Unspecified vulnerability in (1) System Consultants La!Cooda WIZ 1.4.0 and earlier and (2) SpaceTag LacoodaST 2.1.3 and earlier allows remote attackers to execute arbitrary PHP scripts, and delete files, read files, and possibly have unknown other impact."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-07T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"JVN#53886050","tags":["third-party-advisory","x_refsource_JVN"],"url":"http://jvn.jp/en/jp/JVN53886050/index.html"},{"name":"lacooda-unspecified-code-execution(44594)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44594"},{"name":"30791","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/30791"},{"name":"31574","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/31574"},{"tags":["x_refsource_CONFIRM"],"url":"http://wiz.syscon.co.jp/Details.htm"},{"name":"31582","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/31582"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-3737","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unspecified vulnerability in (1) System Consultants La!Cooda WIZ 1.4.0 and earlier and (2) SpaceTag LacoodaST 2.1.3 and earlier allows remote attackers to execute arbitrary PHP scripts, and delete files, read files, and possibly have unknown other impact."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"JVN#53886050","refsource":"JVN","url":"http://jvn.jp/en/jp/JVN53886050/index.html"},{"name":"lacooda-unspecified-code-execution(44594)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44594"},{"name":"30791","refsource":"BID","url":"http://www.securityfocus.com/bid/30791"},{"name":"31574","refsource":"SECUNIA","url":"http://secunia.com/advisories/31574"},{"name":"http://wiz.syscon.co.jp/Details.htm","refsource":"CONFIRM","url":"http://wiz.syscon.co.jp/Details.htm"},{"name":"31582","refsource":"SECUNIA","url":"http://secunia.com/advisories/31582"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-3737","datePublished":"2008-08-27T20:00:00.000Z","dateReserved":"2008-08-20T00:00:00.000Z","dateUpdated":"2024-08-07T09:52:59.265Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-08-27 20:41:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-94","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:spacetag:lacoodast:*:*:*:*:*:*:*:*","versionEndIncluding":"2.1.3","matchCriteriaId":"0FC83794-AF5E-4132-9D39-DDFCC4676AAC"},{"vulnerable":true,"criteria":"cpe:2.3:a:system_consultants:la_cooda_wiz:*:*:*:*:*:*:*:*","versionEndIncluding":"1.4.0","matchCriteriaId":"D37B18AD-ED65-4D9B-92D1-80C0D74E98CB"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"3737","Ordinal":"1","Title":"CVE-2008-3737","CVE":"CVE-2008-3737","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"3737","Ordinal":"1","NoteData":"Unspecified vulnerability in (1) System Consultants La!Cooda WIZ 1.4.0 and earlier and (2) SpaceTag LacoodaST 2.1.3 and earlier allows remote attackers to execute arbitrary PHP scripts, and delete files, read files, and possibly have unknown other impact.","Type":"Description","Title":"CVE-2008-3737"},{"CveYear":"2008","CveId":"3737","Ordinal":"2","NoteData":"2008-08-27","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"3737","Ordinal":"3","NoteData":"2017-08-07","Type":"Other","Title":"Modified"}]}}}