← Vulnerability feed

Vulnerability record · CVE-2016-6600 · published 23 January 2017

CVE-2016-6600: ZOHO WebNMS Framework file upload path traversal allows JSP execution

Zohocorp · Webnms Framework

ZOHO WebNMS Framework 5.2 and 5.2 SP1 contain a directory traversal flaw in the file upload servlet (servlets/FileUploadServlet). The fileName parameter accepts .. sequences, letting a remote attacker write files outside the intended upload directory, including JSP files that the server then executes. Because the endpoint is reachable without authentication and the result is code execution, this is a full compromise of the application server.

9.8 CVSS 3.0 Critical EPSS 91% · top 0.2% CWE-22 · Path traversal
9.8CVSS 3.0 base score, v2 7.5
91%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References, 10 tagged exploit
17 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in the file upload functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to upload and execute arbitrary JSP files via a .. (dot dot) in the fileName parameter to servlets/FileUploadServlet.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable path traversal leading to remote code execution, with public exploit code and a very high EPSS score.

What it is

ZOHO WebNMS Framework 5.2 and 5.2 SP1 contain a directory traversal flaw in the file upload servlet (servlets/FileUploadServlet). The fileName parameter accepts .. sequences, letting a remote attacker write files outside the intended upload directory, including JSP files that the server then executes. Because the endpoint is reachable without authentication and the result is code execution, this is a full compromise of the application server.

Impact

An unauthenticated remote attacker can upload and execute arbitrary JSP code, gaining code execution in the context of the WebNMS server and full control of confidentiality, integrity and availability of the host.

Attack surface

Reached over the network via HTTP requests to servlets/FileUploadServlet with a crafted fileName parameter. The CVSS vector shows no privileges and no user interaction required, so the upload endpoint is exposed to unauthenticated callers.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.90554, 99.8th percentile) and multiple references are tagged Exploit, including public PoC and Exploit-DB entries, indicating mature public exploit code.

What to do

  • Apply the vendor fix or upgrade WebNMS Framework beyond 5.2 SP1; check the WebNMS forum advisory for the supported remediation path.
  • If patching is not immediately possible, restrict network access to servlets/FileUploadServlet and the WebNMS management interface to trusted hosts only.
  • Validate and canonicalize the fileName parameter server-side, rejecting any path separators or .. sequences, and store uploads outside the web root.
  • Disable execution of uploaded content (for example, block JSP execution in upload directories) and run the WebNMS service with least privilege.
  • Monitor the WebNMS forum and vendor channels for updated guidance, since the record does not name a fixed version.

Detection

  • Inspect web and proxy logs for POST requests to servlets/FileUploadServlet containing .. or encoded traversal sequences in the fileName parameter.
  • Alert on newly created .jsp files in web-accessible or upload directories on WebNMS hosts.
  • Monitor for unexpected child processes or outbound connections spawned by the WebNMS Java process, which may indicate uploaded JSP execution.
  • Baseline and review file writes by the WebNMS service account for paths outside expected upload locations.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-6600 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-6602ZOHO WebNMS Framework weak password obfuscation exposes cleartext credentialsZOHO WebNMS Framework 5.2 and 5.2 SP1 store passwords using a weak obfuscation algorithm rather than proper hashing. Anyone who can read WEB-INF/conf…EPSS 55%analysed9.8CVE-2016-6603ZOHO WebNMS Framework authentication bypass via UserName headerZOHO WebNMS Framework 5.2 and 5.2 SP1 trusts the UserName HTTP header for identity, allowing remote attackers to bypass authentication and impersonat…EPSS 87%analysed7.5CVE-2016-6601ZOHO WebNMS Framework FetchFile path traversal allows arbitrary file readThe file download servlet servlets/FetchFile in ZOHO WebNMS Framework 5.2 and 5.2 SP1 fails to sanitize the fileName parameter, allowing directory tr…EPSS 97%analysed9.8CVE-2026-93616Checkpoint multi-domain security management path traversal vulnerabilityA directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Managem…KEVEPSS 20%10.0CVE-2026-85706GitLab CE/EE repository commits API path traversal allows unauthenticated file readGitLab CE/EE contains improper path confinement and missing authentication enforcement in the repository commits API, allowing an unauthenticated use…KEVEPSS 91%analysed5.3CVE-2026-66384JFrog Artifactory path traversal in Docker cache pathAn authenticated user can write data outside the intended Docker cache path under specific remote-repository conditions in JFrog Artifactory. The fla…KEVEPSS 0.66%analysed9.8CVE-2026-59310VMware vCenter Syslog server path traversal leads to RCEVMware vCenter's Syslog server is affected by a directory traversal flaw (CWE-22) that allows a remote, unauthenticated attacker to execute arbitrary…KEVEPSS 2.6%analysed10.0CVE-2026-48282Adobe ColdFusion path traversal leads to remote code executionColdFusion versions 2025.9, 2023.20 and earlier contain a path traversal flaw (CWE-22) that allows an unauthenticated remote attacker to reach files …KEVEPSS 42%analysed

Source: NIST National Vulnerability Database (record CVE-2016-6600), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.