Loading
Directory traversal vulnerability in the file upload functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to upload and execute arbitrary JSP files via a .. (dot dot) in the fileName parameter to servlets/FileUploadServlet.
Use CWE-22, Zohocorp vendor hub and Webnms Framework product page to widen CVE-2016-6600 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2016-6603, CVE-2016-6602 and CVE-2016-6601 for nearby disclosures in the same product family. Additional editorial context is available in Cybersecurity Weekly Roundup: April 27, 2026 — Critical Zero-Days and Framework Failures.