Directory traversal vulnerability in Cybele Software Thinfinity Remote Desktop Workstation 3.0.0.3 32-bit and 64-bit allows remote attackers to download arbitrary files via a .. (dot dot) in an unspecified parameter.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1429
Reference (s):
- http://www.cybelesoft.com/blog/index.php/cybele-software-inc-security-bulletin-2
- https://www.perspectiverisk.com/security-advisory-thinfinity-remote-desktop-workstation-directory-traversal/