Directory traversal vulnerability in Cybele Software Thinfinity Remote Desktop Workstation 3.0.0.3 32-bit and 64-bit allows remote attackers to download arbitrary files via a .. (dot dot) in an unspecified parameter.
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Link | Tags |
---|---|
http://www.cybelesoft.com/blog/index.php/cybele-software-inc-security-bulletin-2 | vendor advisory |
https://www.perspectiverisk.com/security-advisory-thinfinity-remote-desktop-workstation-directory-traversal/ | third party advisory |