CVE-2016-6600: Zohocorp Webnms Framework

Critical severity, CVSS 9.8. EPSS: 90.8% chance of exploitation in the next 30 days.

Directory traversal vulnerability in the file upload functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to upload and execute arbitrary JSP files via a .. (dot dot) in the fileName parameter to servlets/FileUploadServlet.

Affected products

  • Zohocorp Webnms Framework: version 5.2 only

Published 2017-01-23. Last modified 2026-06-17.