CVE-2015-6584
EPSS 0.24%DataTable Vulnerable to Cross-Site Scripting
Published: 8/31/2020Modified: 4/28/2026
Description
Cross-site scripting (XSS) vulnerability in the DataTables plugin 1.10.8 and earlier for jQuery allows remote attackers to inject arbitrary web script or HTML via the scripts parameter to media/unit_testing/templates/6776.php.
Affected packages (3)
- Debian/datatables.jsfrom 0, < 1.10.9+dfsg-1
- npm/datatablesfrom 0, < 1.10.10
- Packagist/datatables/datatablesfrom 0, < 1.10.10
References (12)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2015-6584
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2015-6584
- PATCHhttps://github.com/DataTables/DataTables
- WEBhttp://packetstormsecurity.com/files/133555/DataTables-1.10.8-Cross-Site-Scripting.html
- WEBhttp://seclists.org/fulldisclosure/2015/Sep/37
- WEBhttps://github.com/DataTables/DataTables/issues/602
- WEBhttps://github.com/DataTables/DataTablesSrc/commit/ccf86dc5982bd8e16d
- WEBhttps://github.com/DataTables/DataTablesSrc/commits/1.10.10?after=9780a3693572757d87bf70e48bd7555faf974f28+34&branch=1.10.10&qualified_name=refs%2Ftags%2F1.10.10
- WEBhttps://www.netsparker.com/cve-2015-6384-xss-vulnerability-identified-in-datatables
- WEBhttps://www.npmjs.com/advisories/5
- WEBhttp://www.securityfocus.com/archive/1/536437/100/0/threaded
- WEBhttp://www.securityfocus.com/archive/1/archive/1/536437/100/0/threaded