CVE-2015-5667

Cross-site scripting (XSS) vulnerability in the HTML-Scrubber module before 0.15 for Perl, when the comment feature is enabled, allows remote attackers to inject arbitrary web script or HTML via a crafted comment.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.6 UNKNOWN
NETWORK
HIGH
AV:N/AC:H/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 80.36%
Affected Products (NVD)
VendorProductVersion
html-scrubber_projecthtml-scrubber
𝑥
≤ 0.14
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libhtml-scrubber-perl
bookworm
0.19-2
fixed
bullseye
0.19-1
fixed
sid
0.19-2
fixed
trixie
0.19-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libhtml-scrubber-perl
artful
not-affected
bionic
not-affected
cosmic
not-affected
precise
ignored
trusty
Fixed 0.11-1+deb8u1build0.14.04.1
released
vivid
ignored
wily
ignored
xenial
not-affected
yakkety
not-affected
zesty
not-affected
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
perl-HTML-Scrubber
Amazon Linux 1
0:0.15-1.5.amzn1
fixed