Description
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
Remediation
References
Related Vulnerabilities
WordPress Plugin Easy Custom Sidebars Unspecified Vulnerability (1.0.1)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-1428)
Oracle Database Server CVE-2011-2238 Vulnerability (CVE-2011-2238)
Joomla! Core 3.x.x Arbitrary File Upload (3.0.0 - 3.1.4)
PHP Resource Management Errors Vulnerability (CVE-2002-2309)