ZOHO WebNMS Framework 5.2 and 5.2 SP1 contain a directory traversal vulnerability in the file-download functionality exposed through the FetchFile servlet. The servlet fails to properly restrict path traversal sequences supplied in the fileName parameter, allowing a remote attacker to request files outside the intended download directory.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit auxiliary module targeting WebNMS Framework Server 5.2 and 5.2 SP1 (Windows and Linux). The module exploits two vulnerabilities (CVE-2016-6601 and CVE-2016-6602): an unauthenticated file download via the FetchFile servlet, and weak password obfuscation. The exploit sends HTTP GET requests to download the 'conf/securitydbData.xml' file, which contains user credentials, and then deobfuscates the passwords using a custom algorithm. Extracted credentials are saved in a CSV file. The module is operational and can be used to extract all user credentials from a vulnerable WebNMS server without authentication. The only file in the repository is a Ruby script designed for use within the Metasploit framework.
This repository contains a single Metasploit auxiliary module targeting a directory traversal vulnerability (CVE-2016-6601) in WebNMS Framework Server 5.2 and 5.2 SP1. The exploit abuses the FetchFile servlet, which is accessible over HTTP (default port 9090), to download arbitrary text files from the server's filesystem by sending crafted GET requests with directory traversal sequences in the fileName parameter. The module is capable of downloading only text files (binary files may be mangled) and, on Windows, is limited to files on the same drive as the WebNMS installation. The code is written in Ruby and is structured as a typical Metasploit module, with configurable options for the target URI, file path, traversal path, and traversal depth. The main attack vector is network-based, exploiting an unauthenticated HTTP endpoint. The module is operational and provides the attacker with the ability to retrieve sensitive files from vulnerable servers.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.