
Exploit for CVE-2021-40539: RCE in Zoho ManageEngine ADSelfService Plus. Includes detection script, Fofa search syntax, and webshell deployment for penetration testing.
CVE-2021-40539: ADSelfService Plus RCE Vulnerability
CVE-2021-40539 Zoho ManageEngine ADSelfService Plus 6113 and earlier versions have a REST API authentication bypass vulnerability. Remote attackers can exploit this vulnerability to control affected systems. This vulnerability has a CVSS score of 9.33 and a severity rating of Critical.
# Fofa搜索语法
"ADSelfService"
app="ZOHO-ManageEngine-ADSelfService"
header="JSESSIONIDADSSP" //推荐
Step 2: Randomly find targets and use the following detection script to test for the vulnerability....
https://github.com/synacktiv/CVE-2021-40539/blob/main/exploit.py
使用方式:
C:\Users\26629\Desktop\CVE-2021-40539-main>python39 exploit.py
usage: exploit.py [-h] -t TARGET [-w WEBSHELL] [-j JAVA_CLASS] [-s]
exploit.py: error: the following arguments are required: -t/--target
Step 3: Use Godzilla to connect and perform verification testing.... https://ip/help/admin-guide/test.jsp
I uploaded a batch detection script; everyone can download it and continue to improve it.