PatchSiren cyber security CVE debrief
CVE-2016-6600 Zohocorp CVE debrief
CVE-2016-6600 is a critical directory traversal flaw in ZOHO WebNMS Framework file upload handling. According to the supplied NVD record, the issue affects WebNMS Framework 5.2 and 5.2 SP1 and can allow remote attackers to upload and execute arbitrary JSP files through the fileName parameter in servlets/FileUploadServlet.
- Vendor
- Zohocorp
- Product
- Webnms Framework
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-23
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-23
- Advisory updated
- 2026-05-13
Who should care
Administrators and developers responsible for ZOHO WebNMS Framework 5.2/5.2 SP1 deployments, especially any system exposing FileUploadServlet or accepting user-controlled uploads.
Technical summary
The supplied NVD metadata maps this issue to CWE-22 (path traversal). The vulnerability description states that a .. sequence in the fileName parameter can bypass intended upload path restrictions. In the described impact, that traversal can be used to place a JSP file in a location where it may be executed by the server, creating a remote code execution risk on affected deployments.
Defensive priority
Immediate. The CVSS 3.0 base score is 9.8/CRITICAL, and the attack vector is network-based with no privileges or user interaction required.
Recommended defensive actions
- Inventory deployments to confirm whether ZOHO WebNMS Framework 5.2 or 5.2 SP1 is in use.
- Restrict or disable access to servlets/FileUploadServlet from untrusted networks until a vendor-supported fix is in place.
- Validate and canonicalize uploaded filenames on the server side so path traversal sequences are rejected.
- Prevent execution of JSP or other server-side script files in upload directories.
- Review logs and file-system locations used for uploads for unexpected JSP or other webshell-like files.
- Follow vendor and NVD-linked advisories for any available patch, workaround, or upgrade path.
Evidence notes
Supported by the supplied NVD record: CVE-2016-6600 affects ZOHO WebNMS Framework 5.2 and 5.2 SP1, is classified as CWE-22, and has the CVSS vector CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The supplied metadata also lists third-party advisories and exploit references, but no remediation details were included in the source corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-6600 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-6600
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-6600 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-6600
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://blogs.securiteam.com/index.php/archives/2712
[email protected] - Exploit, Technical Description, Third Party Advisory
-
Source reference
Unverified legacy reference
URL: https://forums.webnms.com/topic/recent-vulnerabilities-in-webnms-and-how-to-protect-the-server-against-them
-
Source reference
Unverified legacy reference
URL: https://github.com/pedrib/PoC/blob/master/advisories/webnms-5.2-sp1-pwn.txt
[email protected] - Exploit
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.