Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution via the Smart Update Manager (SUM) servlet.
- http://packetstormsecurity.com/files/164231/ManageEngine-OpManager-SumPDU-Java-Deserialization.html
- https://github.com/20142995/nuclei-templates
- https://github.com/20142995/sectool
- https://github.com/ARPSyndicate/cvemon
- https://github.com/AdeliaNitzsche/Java-Deserialization-Cheat-Sheet
- https://github.com/BrittanyKuhn/javascript-tutorial
- https://github.com/GrrrDog/Java-Deserialization-Cheat-Sheet
- https://github.com/HimmelAward/Goby_POC
- https://github.com/NyxAzrael/Goby_POC
- https://github.com/Z0fhack/Goby_POC
- https://github.com/cyb3r-w0lf/nuclei-template-collection
- https://github.com/intrigueio/cve-2020-28653-poc
- https://github.com/krlabs/dnsbind-vulnerabilities
- https://github.com/mr-r3bot/ManageEngine-CVE-2020-28653
- https://github.com/nomi-sec/PoC-in-GitHub
- https://github.com/tuo4n8/CVE-2020-28653