CVE-2016-20097
- EPSS 0.47%
- Veröffentlicht 11.08.2026 18:17:16
- Zuletzt bearbeitet 14.08.2026 19:17:11
Weaver (Fanwei) E-cology 8.0 contains a SQL injection vulnerability in the SignatureDownLoad servlet that allows unauthenticated remote attackers to read arbitrary files by injecting a UNION SELECT payload into the markId GET parameter, which is conc...
CVE-2022-50997
- EPSS 0.46%
- Veröffentlicht 11.08.2026 18:17:16
- Zuletzt bearbeitet 11.08.2026 18:17:16
Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in the HrmCareerApplyPerView.jsp endpoint that allows unauthenticated remote attackers to extract arbitrary data from the backend database by manipulating the id GET paramete...
CVE-2022-4995
- EPSS 0.69%
- Veröffentlicht 07.08.2026 14:39:50
- Zuletzt bearbeitet 07.08.2026 19:17:32
Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to upload arbitrary files, including JSP webshells, by submitting a multipart/form-data POST request to /workrelat...
CVE-2022-50992
- EPSS 0.71%
- Veröffentlicht 30.04.2026 16:09:06
- Zuletzt bearbeitet 30.04.2026 17:19:57
Weaver (Fanwei) E-cology 9.5 versions prior to 10.52 contain an arbitrary file read vulnerability in the XmlRpcServlet interface at the XML-RPC endpoint that allows unauthenticated remote attackers to read arbitrary files by supplying file paths to t...
CVE-2026-22679
- EPSS 21.48%
- Veröffentlicht 07.04.2026 12:51:22
- Zuletzt bearbeitet 05.05.2026 14:16:07
Weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution vulnerability in the /papi/esearch/data/devops/dubboApi/debug/method endpoint that allows attackers to execute arbitrary commands by invoking ex...
CVE-2025-34038
- EPSS 1.84%
- Veröffentlicht 24.06.2025 01:06:35
- Zuletzt bearbeitet 27.01.2026 21:15:56
A SQL injection vulnerability exists in Weaver e-cology 8.0 via the getdata.jsp endpoint. The application directly passes unsanitized user input from the sql parameter into a database query within the getSelectAllIds(sql, type) method, reachable thro...
CVE-2024-48069
- EPSS 0.4%
- Veröffentlicht 19.11.2024 18:15:21
- Zuletzt bearbeitet 05.06.2025 13:54:55
A vulnerability was found in Weaver E-cology allows attackers use race conditions to bypass security mechanisms to upload malicious files and control server privileges
CVE-2024-48070
- EPSS 0.7%
- Veröffentlicht 19.11.2024 18:15:21
- Zuletzt bearbeitet 05.06.2025 13:55:09
An issue in Weaver E-cology v. attackers construct special requests to insert remote malicious code and to trigger malicious code execution, and control server privileges
CVE-2024-48072
- EPSS 0.43%
- Veröffentlicht 19.11.2024 18:15:21
- Zuletzt bearbeitet 05.06.2025 13:58:30
Weaver Ecology v9.* was discovered to contain a SQL injection vulnerability via the component /mobilemode/Action.jsp?invoker=com.weaver.formmodel.mobile.mec.servlet.MECAction&action=getFieldTriggerValue&searchField=*&fromTable=HrmResourceManager&wher...
CVE-2024-48071
- EPSS 0.84%
- Veröffentlicht 19.11.2024 17:15:09
- Zuletzt bearbeitet 24.09.2025 19:08:16
E-cology has a directory traversal vulnerability. An attacker can exploit this vulnerability to delete the server directory, causing the server to permanently deny service.