8957 vulnerabilities classified as CWE-89 (SQL命令中使用的特殊元素转义处理不恰当(SQL注入)). AI Chinese analysis included.
CWE-89 represents a critical input validation weakness where software constructs SQL commands using untrusted data without properly sanitizing special characters. Attackers typically exploit this vulnerability by injecting malicious SQL syntax into user-facing inputs, such as login fields or search queries, to manipulate the database’s behavior. This exploitation can lead to unauthorized data access, data modification, or complete system compromise by bypassing authentication or executing arbitrary commands. Developers mitigate this risk by implementing strict input validation and, most effectively, using parameterized queries or prepared statements. These techniques ensure that user input is treated strictly as data rather than executable code, thereby preventing the injection of malicious SQL elements. By separating code logic from data inputs, applications maintain integrity and protect sensitive information from unauthorized manipulation.
... string userName = ctx.getAuthenticatedUserName(); string query = "SELECT * FROM items WHERE owner = '" + userName + "' AND itemname = '" + ItemName.Text + "'"; sda = new SqlDataAdapter(query, conn); DataTable dt = new DataTable(); sda.Fill(dt); ...SELECT * FROM items WHERE owner = <userName> AND itemname = <itemName>;| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2016-10556 | sequelize SQL注入漏洞 — sequelize node module | 9.1 | - | 2018-05-29 |
| CVE-2018-7501 | 多款Advantech产品SQL注入漏洞 — WebAccess | 7.5 | - | 2018-05-15 |
| CVE-2018-8914 | Synology Media Server SQL注入漏洞 — Media Server | 9.8 | - | 2018-05-10 |
| CVE-2018-1096 | Foreman dashboard controller SQL注入漏洞 — Foreman | 8.1 | - | 2018-04-05 |
| CVE-2018-7528 | Geutebrück G-Cam/EFD-2250和Topline TopFD-2125 SQL注入漏洞 — Geutebrück G-Cam/EFD-2250 (part n° 5.02024) firmware and Topline TopFD-2125 (part n° 5.02820) firmware | 9.1 | - | 2018-03-22 |
| CVE-2017-0914 | GitLab Community Edition和Enterprise Edition MilestoneFinder组件SQL注入漏洞 — GitLab Community and Enterprise Editions | 7.5 | - | 2018-03-21 |
| CVE-2017-17412 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2017-17414 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2017-17415 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2017-17416 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2017-17417 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2017-17418 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2017-17419 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2017-17420 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2017-17421 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2017-17422 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2017-17423 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2017-17424 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2017-17425 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2017-17652 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2017-17653 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2017-17654 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2017-17655 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2017-17656 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2017-17657 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2017-17658 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2017-17659 | Quest NetVault Backup SQL注入漏洞 — Quest NetVault Backup | 9.8 | - | 2018-02-08 |
| CVE-2018-0120 | Cisco Unified Communications Manager SQL注入漏洞 — Cisco Unified Communications Manager | 4.3 | - | 2018-02-08 |
| CVE-2018-5443 | Advantech WebAccess/SCADA SQL注入漏洞 — Advantech WebAccess/SCADA | 9.4 | - | 2018-01-25 |
| CVE-2017-12729 | Moxa SoftCMS Live Viewer SQL注入漏洞 — Moxa SoftCMS Live Viewer | 9.8 | - | 2018-01-18 |
Vulnerabilities classified as CWE-89 (SQL命令中使用的特殊元素转义处理不恰当(SQL注入)) represent 8957 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.