Security Advisory

CVE-2016-6601

7.5
HIGH

Vulnerability Description

Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to read arbitrary files via a .. (dot dot) in the fileName parameter to servlets/FetchFile.
Published Date January 23, 2017
Official Source NIST NVD Advisory