ZOHO WebNMS Framework before version 5.2 SP1 is vulnerable local file inclusion which allows an attacker to read arbitrary files via a .. (dot dot) in the fileName parameter to servlets/FetchFile.
View the template here CVE-2016-6601.yaml
References:
http://www.rapid7.com/db/modules/auxiliary/admin/http/webnms_cred_disclosure