Cross-site scripting (XSS) vulnerability in Cisco AnyConnect Secure Mobility Client 3.1(.02043) and earlier and Cisco HostScan Engine 3.1(.05183) and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving an applet-path URL, aka Bug IDs CSCup82990 and CSCuq80149.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: cisco

Published: 2015-02-03T22:00:00

Updated: 2017-09-07T15:57:01

Reserved: 2014-10-08T00:00:00


Link: CVE-2014-8021

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2015-02-03T22:59:01.253

Modified: 2017-09-08T01:29:19.607


Link: CVE-2014-8021

JSON object: View

cve-icon Redhat Information

No data.

CWE