UBUNTU-CVE-2015-6584
Dashboard / Vulnerabilities / UBUNTU-CVE-2015-6584
Summary:
Details: Cross-site scripting (XSS) vulnerability in the DataTables plugin 1.10.8 and earlier for jQuery allows remote attackers to inject arbitrary web script or HTML via the scripts parameter to media/unit_testing/templates/6776.php.
References: https://ubuntu.com/security/CVE-2015-6584, http://www.securityfocus.com/archive/1/archive/1/536437/100/0/threaded, https://www.netsparker.com/cve-2015-6384-xss-vulnerability-identified-in-datatables/, https://github.com/DataTables/DataTables/issues/602, https://github.com/DataTables/DataTablesSrc/commit/ccf86dc5982bd8e16d, https://nodesecurity.io/advisories/5, https://www.cve.org/CVERecord?id=CVE-2015-6584
Affected packages
Package
Name: datatables.js
Purl: pkg:deb/ubuntu/[email protected]+dfsg-1?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
