References https://stack.chaitin.com/vuldb/detail/324e18f4-00e7-496d-b154-e2c9d14d3039 https://avd.aliyun.com/detail?id=AVD-2016-6600 https://nvd.nist.gov/vuln/detail/CVE-2016-6601 https://github.com/advisories/GHSA-xh3h-35f7-mgq7 https://nvd.nist.gov/vuln/detail/CVE-2016-6600 http://packetstormsecurity.com/files/138244/WebNMS-Framework-5.2-SP1-Traversal-Weak-Obfuscation-User-Impersonation.html https://raw.githubusercontent.com/projectdiscovery/nuclei-templates/master/cves/2016/CVE-2016-6601.yaml
Related VulnerabilitiesPoCCVE-2026-39352: Frappe Framework < 16.15.0 - Arbitrary File Read via render_include Path TraversalPoCfrappe-default-login: Frappe Framework - Default Login CredentialsPoCCVE-2025-41242: Spring Framework - Path TraversalPoCCVE-2024-38819: Spring Framework Path Traversal in Functional Web FrameworksServerless Framework 未授权 命令注入漏洞Astro Web Framework Cloudflare /_image 服务器端请求伪造漏洞(CVE-2025-58179)Spring Framework路径遍历漏洞(CVE-2024-38819)Vmware Spring Framework 逻辑缺陷漏洞OpenOrange Business Framework访问控制错误漏洞(CVE-2024-42048)PoCCVE-2020-0646: Microsoft .NET Framework - Remote Code ExecutionPoCspring4shell-CVE-2022-22965: Spring Framework RCE via Data Binding on JDK 9+PoCCVE-2016-6601: ZOHO WebNMS Framework <5.2 SP1 - Local File Inclusion