.. / CVE-2021-44077

Exploit for Zoho ManageEngine ServiceDesk Plus - Remote Code Execution (CVE-2021-44077)

Description:

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution.

Nuclei Template

View the template here CVE-2021-44077.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-44077.yaml
Copy

References:

https://unit42.paloaltonetworks.com/tiltedtemple-manageengine-servicedesk-plus/
https://github.com/horizon3ai/CVE-2021-44077
https://www.cisa.gov/uscert/ncas/alerts/aa21-336a
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/manageengine_servicedesk_plus_cve_2021_44077.rb
https://nvd.nist.gov/vuln/detail/CVE-2021-44077