Vulnerabilities
Vulnerable Software
Cybelesoft:  Security Vulnerabilities
Cybele Thinfinity VirtualUI 2.5.17.2 allows ../ path traversal that can be used for data exfiltration. This enables files outside of the web directory to be retrieved if the exact location is known and the user has permissions.
CVSS Score
6.5
EPSS Score
0.011
Published
2020-06-04
Cybele Thinfinity VirtualUI 2.5.17.2 allows HTTP response splitting via the mimetype parameter within a PDF viewer request, as demonstrated by an example.pdf?mimetype= substring. The victim user must load an application request to view a PDF, containing the malicious payload. This results in a reflected XSS payload being executed.
CVSS Score
6.1
EPSS Score
0.008
Published
2020-06-04
Directory traversal vulnerability in Cybele Software Thinfinity Remote Desktop Workstation 3.0.0.3 32-bit and 64-bit allows remote attackers to download arbitrary files via a .. (dot dot) in an unspecified parameter.
CVSS Score
7.5
EPSS Score
0.02
Published
2017-10-06


Contact Us

Shodan ® - All rights reserved