CWE-77 在命令中使用的特殊元素转义处理不恰当(命令注入) 类弱点 1237 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-77即命令注入,属于输入验证缺陷。攻击者通过构造包含特殊字符的恶意输入,篡改后端系统命令,从而执行任意指令或获取敏感数据。开发者应避免直接拼接用户输入,需采用白名单过滤、参数化调用或安全API替代系统命令执行,确保输入被严格限制在预期范围内,从源头阻断注入风险。
prompt = "Explain the difference between {} and {}".format(arg1, arg2) result = invokeChatbot(prompt) resultHTML = encodeForHTML(result) print resultHTMLExplain the difference between CWE-77 and CWE-78my $arg = GetArgument("filename"); do_listing($arg); sub do_listing { my($fname) = @_; if (! validate_name($fname)) { print "Error: name is not well-formed!\n"; return; } # build command my $cmd = "/bin/ls -l $fname"; system($cmd); } sub validate_name { my($name) = @_; if ($name =~ /^[\w\-]+$/) { return(1); } else { return(0); } }if ($name =~ /^\w[\w\-]+$/) ...| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2017-12341 | 多款Cisco产品Cisco NX-OS System Software 命令注入漏洞 — Cisco NX-OS | 6.7 | - | 2017-11-30 |
| CVE-2017-12352 | Cisco Application Policy Infrastructure Controller 命令注入漏洞 — Cisco Application Policy Infrastructure Controller | 6.7 | - | 2017-11-30 |
| CVE-2017-12305 | Cisco IP Phone 8800系列debug界面命令注入漏洞 — Cisco IP Phone 8800 Series | 6.7 | - | 2017-11-16 |
| CVE-2017-6048 | Satel Iberia SenNet Data Logger和Electricity Meters 命令注入漏洞 — Satel Iberia SenNet Data Logger and Electricity Meters | 8.8 | - | 2017-05-19 |
| CVE-2016-10329 | Synology Photo Station 命令注入漏洞 — Synology Photo Station | 9.8 | - | 2017-05-12 |
| CVE-2014-9188 | Schneider Electric ProClima MDraw30.ocx 缓冲区溢出漏洞 — ProClima | 9.8 | - | 2014-12-27 |
| CVE-2014-0773 | Advantech WebAccess‘CreateProcess’方法安全漏洞 — WebAccess | 8.1 | - | 2014-04-12 |
CWE-77(在命令中使用的特殊元素转义处理不恰当(命令注入)) 是常见的弱点类别,本平台收录该类弱点关联的 1237 条 CVE 漏洞。