Vulnerability record · CVE-2016-6600 · published 23 January 2017
CVE-2016-6600: ZOHO WebNMS Framework file upload path traversal allows JSP execution
Zohocorp · Webnms Framework
ZOHO WebNMS Framework 5.2 and 5.2 SP1 contain a directory traversal flaw in the file upload servlet (servlets/FileUploadServlet). The fileName parameter accepts .. sequences, letting a remote attacker write files outside the intended upload directory, including JSP files that the server then executes. Because the endpoint is reachable without authentication and the result is code execution, this is a full compromise of the application server.
Description
Directory traversal vulnerability in the file upload functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to upload and execute arbitrary JSP files via a .. (dot dot) in the fileName parameter to servlets/FileUploadServlet.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable path traversal leading to remote code execution, with public exploit code and a very high EPSS score.
What it is
ZOHO WebNMS Framework 5.2 and 5.2 SP1 contain a directory traversal flaw in the file upload servlet (servlets/FileUploadServlet). The fileName parameter accepts .. sequences, letting a remote attacker write files outside the intended upload directory, including JSP files that the server then executes. Because the endpoint is reachable without authentication and the result is code execution, this is a full compromise of the application server.
Impact
An unauthenticated remote attacker can upload and execute arbitrary JSP code, gaining code execution in the context of the WebNMS server and full control of confidentiality, integrity and availability of the host.
Attack surface
Reached over the network via HTTP requests to servlets/FileUploadServlet with a crafted fileName parameter. The CVSS vector shows no privileges and no user interaction required, so the upload endpoint is exposed to unauthenticated callers.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.90554, 99.8th percentile) and multiple references are tagged Exploit, including public PoC and Exploit-DB entries, indicating mature public exploit code.
What to do
- Apply the vendor fix or upgrade WebNMS Framework beyond 5.2 SP1; check the WebNMS forum advisory for the supported remediation path.
- If patching is not immediately possible, restrict network access to servlets/FileUploadServlet and the WebNMS management interface to trusted hosts only.
- Validate and canonicalize the fileName parameter server-side, rejecting any path separators or .. sequences, and store uploads outside the web root.
- Disable execution of uploaded content (for example, block JSP execution in upload directories) and run the WebNMS service with least privilege.
- Monitor the WebNMS forum and vendor channels for updated guidance, since the record does not name a fixed version.
Detection
- Inspect web and proxy logs for POST requests to servlets/FileUploadServlet containing .. or encoded traversal sequences in the fileName parameter.
- Alert on newly created .jsp files in web-accessible or upload directories on WebNMS hosts.
- Monitor for unexpected child processes or outbound connections spawned by the WebNMS Java process, which may indicate uploaded JSP execution.
- Baseline and review file writes by the WebNMS service account for paths outside expected upload locations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-6600 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-6600), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.