Security Advisory
CVE-2018-6603
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Promise Technology WebPam Pro-E devices allow remote attackers to conduct XSS, HTTP Response Splitting, and CRLF Injection attacks via JavaScript code in a PHPSESSID cookie.