CVE-2016-6601: Zohocorp Webnms Framework
High severity, CVSS 7.5. EPSS: 97.5% chance of exploitation in the next 30 days.
Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to read arbitrary files via a .. (dot dot) in the fileName parameter to servlets/FetchFile.
Affected products
- Zohocorp Webnms Framework: version 5.2 only
Published 2017-01-23. Last modified 2026-06-17.