Multiple Cisco Products CVE-2014-8021 Cross Site Scripting Vulnerability
BID:72475
Info
Multiple Cisco Products CVE-2014-8021 Cross Site Scripting Vulnerability
| Bugtraq ID: | 72475 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-8021 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 02 2015 12:00AM |
| Updated: | Feb 02 2015 12:00AM |
| Credit: | Cisco |
| Vulnerable: |
Cisco HostScan Engine 0 Cisco AnyConnect Secure Mobility Client 0 |
| Not Vulnerable: | |
Discussion
Multiple Cisco Products CVE-2014-8021 Cross Site Scripting Vulnerability
Multiple Cisco products are prone to a cross-site scripting vulnerability because it fails to properly sanitize the user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
This issue is being tracked by Cisco Bug ID's CSCup82990 and CSCuq80149.
Multiple Cisco products are prone to a cross-site scripting vulnerability because it fails to properly sanitize the user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
This issue is being tracked by Cisco Bug ID's CSCup82990 and CSCuq80149.