CVE-2018-6603

CVE: CVE-2018-6603
Published: 2018-02-07T05:29Z
Description Language: en
Description: Promise Technology WebPam Pro-E devices allow remote attackers to conduct XSS, HTTP Response Splitting, and CRLF Injection attacks via JavaScript code in a PHPSESSID cookie.
References:
http://dfdrconsulting.com/cve-2018-6603-promise-technology-webpam-pro-e-http-response-header-injection-xss/