CVE Tools

Description

Directory traversal vulnerability in the file upload functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to upload and execute arbitrary JSP files via a .. (dot dot) in the fileName parameter to servlets/FileUploadServlet.

In plain language

AI Act now

ZOHO WebNMS Framework 5.2 and 5.2 SP1 have a file upload flaw that can let an internet attacker upload and run malicious code; if your system exposes this upload feature to the internet, you should treat it as urgent.

Executive summary

Directory traversal in ZOHO WebNMS Framework 5.2/5.2 SP1 file upload (CWE-22) allows remote attackers to upload and execute arbitrary JSP files via a crafted fileName containing “..” sequences targeting servlets/FileUploadServlet.

If affected, business impact
Full server compromiseMalware and persistenceOperational disruptionCustomer data exposure

What to do now

  1. Check whether you are running ZOHO WebNMS Framework 5.2 or 5.2 SP1.
  2. Check whether the file upload feature (FileUploadServlet) is reachable from the internet, or accessible from external networks.
  3. If reachable externally, restrict network access so external users cannot reach the WebNMS Framework upload endpoint.
  4. Contact your Zoho/WebNMS support channel and ask for an official fixed version for CVE-2016-6600 (no patch details are available here).
  5. If you can’t get a fixed version quickly, prioritize compensating controls: keep upload functionality disabled (if possible) and ensure it is only reachable from trusted internal networks.
May need vendor / contractor work

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

zohocorp
commercial·INaka manageengine, zoho corp
and 1 more affected products View all →

Exploitability

3 exploit sources identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

2 techniques
Collection
Discovery
View detailed technique mapping

References

and 5 more references View all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2016-6600 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store