CVE-2014-8021
Cisco AnyConnect < 3.1(.02043) & HostScan < 3.1(.05183) XSS via Applet-Path URL
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in Cisco AnyConnect Secure Mobility Client 3.1(.02043) and earlier and Cisco HostScan Engine 3.1(.05183) and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving an applet-path URL, aka Bug IDs CSCup82990 and CSCuq80149.
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/100666
Vendor Advisory x_refsource_confirm
http://tools.cisco.com/security/center/viewAlert.x?alertId=37323
Vendor Advisory vendor-advisory
x_refsource_cisco
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-8021
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/72475
Scores
EPSS
0.0179
EPSS Percentile
76.1%
Details
CWE
CWE-79
Status
published
Products (2)
cisco/anyconnect_secure_mobility_client
< 3.1\(.02043\)
cisco/hostscan_engine
< 3.1\(.05183\)
Published
Feb 03, 2015
Tracked Since
Feb 18, 2026