{"api_version":"1","generated_at":"2026-07-23T12:52:35+00:00","cve":"CVE-2008-3739","urls":{"html":"https://cve.report/CVE-2008-3739","api":"https://cve.report/api/cve/CVE-2008-3739.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-3739","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-3739"},"summary":{"title":"CVE-2008-3739","description":"Cross-site scripting (XSS) vulnerability in (1) System Consultants La!Cooda WIZ 1.4.0 and earlier and (2) SpaceTag LacoodaST 2.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving upload of files containing XSS sequences.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-08-27 20:41:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://jvn.jp/en/jp/JVN27417220/index.html","name":"http://jvn.jp/en/jp/JVN27417220/index.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"JVN#27417220 mysql-lists from AquaGardenSoft Co.,Ltd. vulnerable to cross-site scripting","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://jvn.jp/en/jp/JVN52557009/index.html","name":"http://jvn.jp/en/jp/JVN52557009/index.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"JVN#52557009 La!cooda WIZ and LacoodaST vulnerable to cross-site scripting","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://wiz.syscon.co.jp/Details.htm","name":"http://wiz.syscon.co.jp/Details.htm","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000048.html","name":"http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000048.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.spacetag.jp/modules/products/index.php?id=54","name":"http://www.spacetag.jp/modules/products/index.php?id=54","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://secunia.com/advisories/31574","name":"http://secunia.com/advisories/31574","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"La!cooda WIZ Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44593","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44593","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/31582","name":"http://secunia.com/advisories/31582","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"LacoodaST Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/30791","name":"http://www.securityfocus.com/bid/30791","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"LacoodaST and La!cooda WIZ Multiple Remote Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-3739","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-3739","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"3739","vulnerable":"1","versionEndIncluding":"2.1.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"spacetag","cpe5":"lacoodast","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3739","vulnerable":"1","versionEndIncluding":"1.4.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"system_consultants","cpe5":"la_cooda_wiz","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T09:52:59.531Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"JVN#52557009","tags":["third-party-advisory","x_refsource_JVN","x_transferred"],"url":"http://jvn.jp/en/jp/JVN52557009/index.html"},{"name":"30791","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/30791"},{"name":"JVN#27417220","tags":["third-party-advisory","x_refsource_JVN","x_transferred"],"url":"http://jvn.jp/en/jp/JVN27417220/index.html"},{"name":"31574","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/31574"},{"name":"lacooda-unspecified-xss(44593)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44593"},{"name":"JVNDB-2008-000048","tags":["third-party-advisory","x_refsource_JVNDB","x_transferred"],"url":"http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000048.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://wiz.syscon.co.jp/Details.htm"},{"name":"31582","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/31582"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.spacetag.jp/modules/products/index.php?id=54"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-08-21T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in (1) System Consultants La!Cooda WIZ 1.4.0 and earlier and (2) SpaceTag LacoodaST 2.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving upload of files containing XSS sequences."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-07T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"JVN#52557009","tags":["third-party-advisory","x_refsource_JVN"],"url":"http://jvn.jp/en/jp/JVN52557009/index.html"},{"name":"30791","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/30791"},{"name":"JVN#27417220","tags":["third-party-advisory","x_refsource_JVN"],"url":"http://jvn.jp/en/jp/JVN27417220/index.html"},{"name":"31574","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/31574"},{"name":"lacooda-unspecified-xss(44593)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44593"},{"name":"JVNDB-2008-000048","tags":["third-party-advisory","x_refsource_JVNDB"],"url":"http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000048.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://wiz.syscon.co.jp/Details.htm"},{"name":"31582","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/31582"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.spacetag.jp/modules/products/index.php?id=54"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-3739","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in (1) System Consultants La!Cooda WIZ 1.4.0 and earlier and (2) SpaceTag LacoodaST 2.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving upload of files containing XSS sequences."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"JVN#52557009","refsource":"JVN","url":"http://jvn.jp/en/jp/JVN52557009/index.html"},{"name":"30791","refsource":"BID","url":"http://www.securityfocus.com/bid/30791"},{"name":"JVN#27417220","refsource":"JVN","url":"http://jvn.jp/en/jp/JVN27417220/index.html"},{"name":"31574","refsource":"SECUNIA","url":"http://secunia.com/advisories/31574"},{"name":"lacooda-unspecified-xss(44593)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44593"},{"name":"JVNDB-2008-000048","refsource":"JVNDB","url":"http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000048.html"},{"name":"http://wiz.syscon.co.jp/Details.htm","refsource":"CONFIRM","url":"http://wiz.syscon.co.jp/Details.htm"},{"name":"31582","refsource":"SECUNIA","url":"http://secunia.com/advisories/31582"},{"name":"http://www.spacetag.jp/modules/products/index.php?id=54","refsource":"CONFIRM","url":"http://www.spacetag.jp/modules/products/index.php?id=54"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-3739","datePublished":"2008-08-27T20:00:00.000Z","dateReserved":"2008-08-20T00:00:00.000Z","dateUpdated":"2024-08-07T09:52:59.531Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-08-27 20:41:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:spacetag:lacoodast:*:*:*:*:*:*:*:*","versionEndIncluding":"2.1.3","matchCriteriaId":"0FC83794-AF5E-4132-9D39-DDFCC4676AAC"},{"vulnerable":true,"criteria":"cpe:2.3:a:system_consultants:la_cooda_wiz:*:*:*:*:*:*:*:*","versionEndIncluding":"1.4.0","matchCriteriaId":"D37B18AD-ED65-4D9B-92D1-80C0D74E98CB"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"3739","Ordinal":"1","Title":"CVE-2008-3739","CVE":"CVE-2008-3739","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"3739","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in (1) System Consultants La!Cooda WIZ 1.4.0 and earlier and (2) SpaceTag LacoodaST 2.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving upload of files containing XSS sequences.","Type":"Description","Title":"CVE-2008-3739"},{"CveYear":"2008","CveId":"3739","Ordinal":"2","NoteData":"2008-08-27","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"3739","Ordinal":"3","NoteData":"2017-08-07","Type":"Other","Title":"Modified"}]}}}