CVE-2014-8028: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the web framework in Cisco Secure Access Control System (ACS) allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuq79019.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8028?
CVE-2014-8028 is classified as a high-severity vulnerability due to its potential for exploitation via cross-site scripting.
How do I fix CVE-2014-8028?
To fix CVE-2014-8028, apply the latest security patches provided by Cisco for the Secure Access Control System.
What types of attacks can CVE-2014-8028 facilitate?
CVE-2014-8028 can facilitate cross-site scripting (XSS) attacks, allowing attackers to inject arbitrary web scripts or HTML.
Which software versions are affected by CVE-2014-8028?
CVE-2014-8028 affects Cisco Secure Access Control System versions that have not been patched for this vulnerability.
Can CVE-2014-8028 be exploited remotely?
Yes, CVE-2014-8028 can be exploited remotely by attackers to execute malicious scripts in the context of a user's browser.