A vulnerability was found in Zoho WebNMS Framework 5.2/5.2 SP1. It has been declared as critical. This vulnerability affects unknown code of the file servlets/FileUploadServlet. The manipulation of the argument fileName leads to path traversal.
This vulnerability was named CVE-2016-6600. The attack can be initiated remotely. Furthermore, there is an exploit available.
Attackers have added aggressive social engineering to their arsenal, along with a novel Windows-manipulating persistence mechanism that demands developer vigilance.