ZOHO WebNMS Framework before version 5.2 SP1 is vulnerable local file inclusion which allows an attacker to read arbitrary files via a .. (dot dot) in the fileName parameter to servlets/FetchFile.
id: CVE-2016-6601
info:
name: ZOHO WebNMS Framework <5.2 SP1 - Local File Inclusion
author: 0x_
...