CVE-2016-6603

CRITICAL

ZOHO WebNMS Framework 5.2-5.2 SP1 - Auth Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2016-6603. PoCs published by Pedro Ribeiro.

AI-analyzed exploit summary The document describes multiple vulnerabilities in WebNMS Framework Server 5.2 and 5.2 SP1, including directory traversal leading to RCE, file download via traversal, weak password obfuscation, and user impersonation. CVE-2016-6603 specifically covers user account impersonation via the 'UserName' HTTP header.

Description

ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header.

Exploits (1)

exploitdb WRITEUP
by Pedro Ribeiro · textwebappsjsp
https://www.exploit-db.com/exploits/40229

The document describes multiple vulnerabilities in WebNMS Framework Server 5.2 and 5.2 SP1, including directory traversal leading to RCE, file download via traversal, weak password obfuscation, and user impersonation. CVE-2016-6603 specifically covers user account impersonation via the 'UserName' HTTP header.

Classification
Writeup 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: WebNMS Framework Server 5.2 and 5.2 SP1
No auth needed
Prerequisites: Network access to the WebNMS server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2016/Aug/54
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/92402
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/40229/
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/539159/100/0/threaded
Exploit, Technical Description, Third Party Advisory x_refsource_misc
https://blogs.securiteam.com/index.php/archives/2712

Scores

CVSS v3 9.8
EPSS 0.7032
EPSS Percentile 98.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (1)
zohocorp/webnms_framework 5.2 (2 CPE variants)
Published Jan 23, 2017
Tracked Since Feb 18, 2026