S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 7, 2024

CVE-2016-6601 Scanner

Detects 'Local File Inclusion (LFI)' vulnerability in ZOHO WebNMS Framework affects v. before 5.2 SP1.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
2
Vulnerabilities Found
confirmed findings
References
CVECVE-2016-6601
7.5
CVSS

Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to read arbitrary files via a .. (dot dot) in the fileName parameter to servlets/FetchFile.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

ZOHO WebNMS Framework is a widely used product that serves as a platform for creating network management applications. This framework provides various tools for network management, including network monitoring, device management, and reporting. ZOHO WebNMS Framework is utilized by numerous businesses and organizations across various industries for efficiently managing their networks.

CVE-2016-6601 is a severe vulnerability that was detected in the ZOHO WebNMS Framework. This vulnerability is directly associated with the file download functionality of the framework. Remote attackers could exploit this vulnerability to read any arbitrary file through the ".." in the fileName parameter to servlets/FetchFile. This flaw gives access to unauthorized data, making the management of networks compromised and leaving sensitive information open to cybercriminals.

When exploited, this vulnerability can lead to disastrous consequences. Attackers can gain access to confidential data and use it to their advantage. They can spread malware through the network, steal intellectual property or personal information, and cause reputational damage. All the while, businesses suffer losses in terms of money, credibility, and operations.

At S4E, we specialize in providing cybersecurity solutions designed to keep your digital assets secure. With our cutting-edge features and updates, we guarantee that our platform will keep you protected against the most sophisticated cyber threats. Thanks to our comprehensive approach to cybersecurity, you can rest assured that your networks and devices are protected round the clock. Don't hesitate; sign up today and enjoy the peace of mind that comes with knowing your digital assets are always secure!

 

REFERENCES

Solution Advice

To protect against this vulnerability, there are several precautions that can be taken, including:

  • Ensure that all network devices are regularly updated with the latest security patches and updates.
  • Implement firewall rules to restrict unauthorized access to sensitive network areas.
  • Deploy an intrusion detection system to detect any network anomalies and suspicious activities.
  • Restrict users' file download privileges to specific directories, avoiding access to unrelated files, among other security measures.
  • Conduct regular security audits and employee training to ensure compliance with security protocols.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2016-6601 scanner - Local File Inclusion (LFI) vulnerability in ZOHO WebNMS Framework | S4E