CVE-2016-6601: Path Traversal
Published Jan 23, 2017
·Updated
Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to read arbitrary files via a .. (dot dot) in the fileName parameter to servlets/FetchFile.
Affected Software
2 affected components
ZohoCorp Webnms Framework=5.2
ZohoCorp Webnms Framework=5.2-sp1
Event History
Jan 23, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-6601?
CVE-2016-6601 has a medium severity rating due to its potential to allow attackers to access sensitive files.
2
How do I mitigate CVE-2016-6601?
To mitigate CVE-2016-6601, ensure you update to ZOHO WebNMS Framework version 5.2 SP2 or later.
3
What type of vulnerability is CVE-2016-6601?
CVE-2016-6601 is a directory traversal vulnerability affecting the file download functionality.
4
Can CVE-2016-6601 lead to data breaches?
Yes, CVE-2016-6601 can potentially lead to data breaches by allowing unauthorized file access.
5
Which versions of ZOHO WebNMS Framework are affected by CVE-2016-6601?
CVE-2016-6601 affects ZOHO WebNMS Framework versions 5.2 and 5.2 SP1.