CVE-2016-6600
Description
Directory traversal vulnerability in the file upload functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to upload and execute arbitrary JSP files via a .. (dot dot) in the fileName parameter to servlets/FileUploadServlet.
In plain language
AI Act nowZOHO WebNMS Framework 5.2 and 5.2 SP1 have a file upload flaw that can let an internet attacker upload and run malicious code; if your system exposes this upload feature to the internet, you should treat it as urgent.
Directory traversal in ZOHO WebNMS Framework 5.2/5.2 SP1 file upload (CWE-22) allows remote attackers to upload and execute arbitrary JSP files via a crafted fileName containing “..” sequences targeting servlets/FileUploadServlet.
What to do now
- Check whether you are running ZOHO WebNMS Framework 5.2 or 5.2 SP1.
- Check whether the file upload feature (FileUploadServlet) is reachable from the internet, or accessible from external networks.
- If reachable externally, restrict network access so external users cannot reach the WebNMS Framework upload endpoint.
- Contact your Zoho/WebNMS support channel and ask for an official fixed version for CVE-2016-6600 (no patch details are available here).
- If you can’t get a fixed version quickly, prioritize compensating controls: keep upload functionality disabled (if possible) and ensure it is only reachable from trusted internal networks.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2016-6600 and every CVE in our database. Create a free account — no credit card required.
Create Free Account