CWE-89 SQL命令中使用的特殊元素转义处理不恰当(SQL注入) 类弱点 10452 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-89即SQL注入,属于输入验证类漏洞。当软件未对用户输入进行充分净化或转义,直接将其拼接到SQL命令中时,攻击者可注入恶意SQL代码,从而篡改查询逻辑、绕过身份验证或窃取敏感数据。开发者应避免直接拼接字符串,转而使用参数化查询或预编译语句,确保用户输入仅被视为数据而非可执行代码,从而从根本上阻断注入路径。
... string userName = ctx.getAuthenticatedUserName(); string query = "SELECT * FROM items WHERE owner = '" + userName + "' AND itemname = '" + ItemName.Text + "'"; sda = new SqlDataAdapter(query, conn); DataTable dt = new DataTable(); sda.Fill(dt); ...
SELECT * FROM items WHERE owner = <userName> AND itemname = <itemName>;
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2021-1380 | Cisco Unified Communications Manager 跨站脚本漏洞 — Cisco Unity Connection | 6.1 | Medium | 2021-04-08 |
| CVE-2021-24181 | WordPress SQL注入漏洞 — Tutor LMS – eLearning and online course solution | 6.5 | - | 2021-04-05 |
| CVE-2021-24182 | WordPress SQL注入漏洞 — Tutor LMS – eLearning and online course solution | 6.5 | - | 2021-04-05 |
| CVE-2021-24183 | WordPress 插件 SQL注入漏洞 — Tutor LMS – eLearning and online course solution | 6.5 | - | 2021-04-05 |
| CVE-2021-24185 | WordPress SQL注入漏洞 — Tutor LMS – eLearning and online course solution | 6.5 | - | 2021-04-05 |
| CVE-2021-24186 | WordPress SQL注入漏洞 — Tutor LMS – eLearning and online course solution | 6.5 | - | 2021-04-05 |
| CVE-2021-21380 | Thomas Mortagne xwiki-platform SQL注入漏洞 — xwiki-platform | 7.7 | High | 2021-03-23 |
| CVE-2021-24142 | Wordpress Easy Redirect Manager SQL注入漏洞 — 301 Redirects - Easy Redirect Manager | 7.2 | - | 2021-03-18 |
| CVE-2021-24143 | Wordpress AccessPress Social Icon SQL注入漏洞 — AccessPress Social Icons | 8.8 | - | 2021-03-18 |
| CVE-2021-24149 | Wordpress Modern Events Calendar Lite SQL注入漏洞 — Modern Events Calendar Lite | 8.8 | - | 2021-03-18 |
| CVE-2021-24137 | Wordpress Blog2Social SQL注入漏洞 — Blog2Social: Social Media Auto Post & Scheduler | 8.8 | - | 2021-03-18 |
| CVE-2021-24138 | Wordpress AdRotate SQL注入漏洞 — AdRotate | 7.2 | - | 2021-03-18 |
| CVE-2021-24139 | Wordpress Photo Gallery SQL注入漏洞 — Photo Gallery by 10Web | 9.8 | - | 2021-03-18 |
| CVE-2021-24140 | Wordpress Load More SQL注入漏洞 — Ajax Load More | 9.8 | - | 2021-03-18 |
| CVE-2021-24141 | Wordpress Advanced Database Cleaner SQL注入漏洞 — Advanced Database Cleaner | 7.2 | - | 2021-03-18 |
| CVE-2021-24125 | WordPress SQL注入漏洞 — Contact Form Submissions | 7.2 | - | 2021-03-18 |
| CVE-2021-24130 | Wordpress WP Google Map SQL注入漏洞 — WP Google Map Plugin | 7.2 | - | 2021-03-18 |
| CVE-2021-24131 | Wordpress CleanTalk SQL注入漏洞 — Anti-Spam by CleanTalk | 7.2 | - | 2021-03-18 |
| CVE-2021-24132 | Wordpress Slider by 10Web SQL注入漏洞 — Slider by 10Web | 8.8 | - | 2021-03-18 |
| CVE-2021-22848 | Hgiga MailSherlock SQL注入漏洞 — MailSherlock MSR45/SSR45 | 7.0 | High | 2021-03-18 |
| CVE-2021-22859 | Excellent Infotek Corporation EIC e-document system SQL注入漏洞 — e-document system | 9.8 | Critical | 2021-03-17 |
| CVE-2021-22854 | Soar Cloud System SQL注入漏洞 — HR Portal | 7.5 | High | 2021-02-17 |
| CVE-2021-22856 | CGE property management system SQL注入漏洞 — property management system | 9.8 | Critical | 2021-02-17 |
| CVE-2020-27869 | SolarWinds Network Performance Monitor SQL注入漏洞 — Network Performance Monitor | 8.8 | - | 2021-02-11 |
| CVE-2021-21024 | Adobe Magento SQL注入漏洞 — Magento Commerce | 6.5 | - | 2021-02-11 |
| CVE-2021-22658 | Advantech Iview SQL注入漏洞 — Advantech iView | 9.8 | - | 2021-02-11 |
| CVE-2021-22654 | Advantech Iview SQL注入漏洞 — Advantech iView | 7.5 | - | 2021-02-11 |
| CVE-2021-20016 | Sonicwall SMA100 SQL注入漏洞 — SonicWall SMA100 | 9.8 | - | 2021-02-03 |
| CVE-2020-5427 | Vmware Spring Cloud Data Flow SQL注入漏洞 — Spring Cloud Data Flow | 7.2 | - | 2021-01-27 |
| CVE-2020-5428 | Vmware Spring Cloud Task Application Starters SQL注入漏洞 — Spring Cloud Task | 6.7 | - | 2021-01-27 |
CWE-89(SQL命令中使用的特殊元素转义处理不恰当(SQL注入)) 是常见的弱点类别,本平台收录该类弱点关联的 10452 条 CVE 漏洞。