CWE-89 SQL命令中使用的特殊元素转义处理不恰当(SQL注入) 类弱点 9217 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-89即SQL注入,属于输入验证类漏洞。当软件未对用户输入进行充分净化或转义,直接将其拼接到SQL命令中时,攻击者可注入恶意SQL代码,从而篡改查询逻辑、绕过身份验证或窃取敏感数据。开发者应避免直接拼接字符串,转而使用参数化查询或预编译语句,确保用户输入仅被视为数据而非可执行代码,从而从根本上阻断注入路径。
... string userName = ctx.getAuthenticatedUserName(); string query = "SELECT * FROM items WHERE owner = '" + userName + "' AND itemname = '" + ItemName.Text + "'"; sda = new SqlDataAdapter(query, conn); DataTable dt = new DataTable(); sda.Fill(dt); ...SELECT * FROM items WHERE owner = <userName> AND itemname = <itemName>;| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2017-17417 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2017-17418 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2017-17419 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2017-17420 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2017-17421 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2017-17422 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2017-17423 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2017-17424 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2017-17425 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2017-17652 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2017-17653 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2017-17654 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2017-17655 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2017-17656 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2017-17657 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2017-17658 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2017-17659 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2018-0120 | Cisco Unified Communications Manager SQL注入漏洞 — Cisco Unified Communications Manager | 4.3 | - | 2018-02-08 |
| CVE-2018-5443 | Advantech WebAccess/SCADA SQL注入漏洞 — Advantech WebAccess/SCADA | 9.4 | - | 2018-01-25 |
| CVE-2017-12729 | Moxa SoftCMS Live Viewer SQL注入漏洞 — Moxa SoftCMS Live Viewer | 9.8 | - | 2018-01-18 |
| CVE-2017-16716 | Advantech WebAccess SQL注入漏洞 — Advantech WebAccess | 9.8 | - | 2018-01-05 |
| CVE-2017-12364 | Cisco Prime Service Catalog SQL注入漏洞 — Cisco Prime Service Catalog | 6.5 | - | 2017-11-30 |
| CVE-2017-12302 | Cisco Unified Communications Manager SQL数据库界面SQL注入漏洞 — Cisco Unified Communications Manager | 4.3 | - | 2017-11-16 |
| CVE-2017-12731 | 多款OPW产品SQL注入漏洞 — OPW Fuel Management Systems SiteSentinel Integra and SiteSentinel iSite | 9.8 | - | 2017-09-09 |
| CVE-2017-11161 | Synology Photo Station SQL注入漏洞 — Synology Photo Station | 9.8 | - | 2017-09-08 |
| CVE-2017-12227 | Cisco Emergency Responder SQL注入漏洞 — Cisco Emergency Responder | 5.4 | - | 2017-09-07 |
| CVE-2017-12710 | Advantech WebAccess SQL注入漏洞 — Advantech WebAccess | 7.5 | - | 2017-08-30 |
| CVE-2017-6754 | Cisco Smart Net Total Care Software Collector Appliance SQL注入漏洞 — Cisco Smart Net Total Care Software Collector Appliance | 6.5 | - | 2017-08-07 |
| CVE-2017-6757 | Cisco Unified Communications Manager SQL注入漏洞 — Cisco Unified Communications Manager | 8.8 | - | 2017-08-07 |
| CVE-2017-3221 | AmosConnect 8 SQL注入漏洞 — AmosConnect | 7.5 | - | 2017-07-22 |
CWE-89(SQL命令中使用的特殊元素转义处理不恰当(SQL注入)) 是常见的弱点类别,本平台收录该类弱点关联的 9217 条 CVE 漏洞。