Weaver

E-cology

15 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.47%
  • Veröffentlicht 11.08.2026 18:17:16
  • Zuletzt bearbeitet 14.08.2026 19:17:11

Weaver (Fanwei) E-cology 8.0 contains a SQL injection vulnerability in the SignatureDownLoad servlet that allows unauthenticated remote attackers to read arbitrary files by injecting a UNION SELECT payload into the markId GET parameter, which is conc...

  • EPSS 0.46%
  • Veröffentlicht 11.08.2026 18:17:16
  • Zuletzt bearbeitet 11.08.2026 18:17:16

Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in the HrmCareerApplyPerView.jsp endpoint that allows unauthenticated remote attackers to extract arbitrary data from the backend database by manipulating the id GET paramete...

Exploit
  • EPSS 0.69%
  • Veröffentlicht 07.08.2026 14:39:50
  • Zuletzt bearbeitet 07.08.2026 19:17:32

Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to upload arbitrary files, including JSP webshells, by submitting a multipart/form-data POST request to /workrelat...

Exploit
  • EPSS 0.71%
  • Veröffentlicht 30.04.2026 16:09:06
  • Zuletzt bearbeitet 30.04.2026 17:19:57

Weaver (Fanwei) E-cology 9.5 versions prior to 10.52 contain an arbitrary file read vulnerability in the XmlRpcServlet interface at the XML-RPC endpoint that allows unauthenticated remote attackers to read arbitrary files by supplying file paths to t...

Medienbericht Exploit
  • EPSS 21.48%
  • Veröffentlicht 07.04.2026 12:51:22
  • Zuletzt bearbeitet 05.05.2026 14:16:07

Weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution vulnerability in the /papi/esearch/data/devops/dubboApi/debug/method endpoint that allows attackers to execute arbitrary commands by invoking ex...

Exploit
  • EPSS 1.84%
  • Veröffentlicht 24.06.2025 01:06:35
  • Zuletzt bearbeitet 27.01.2026 21:15:56

A SQL injection vulnerability exists in Weaver e-cology 8.0 via the getdata.jsp endpoint. The application directly passes unsanitized user input from the sql parameter into a database query within the getSelectAllIds(sql, type) method, reachable thro...

  • EPSS 0.4%
  • Veröffentlicht 19.11.2024 18:15:21
  • Zuletzt bearbeitet 05.06.2025 13:54:55

A vulnerability was found in Weaver E-cology allows attackers use race conditions to bypass security mechanisms to upload malicious files and control server privileges

  • EPSS 0.7%
  • Veröffentlicht 19.11.2024 18:15:21
  • Zuletzt bearbeitet 05.06.2025 13:55:09

An issue in Weaver E-cology v. attackers construct special requests to insert remote malicious code and to trigger malicious code execution, and control server privileges

  • EPSS 0.43%
  • Veröffentlicht 19.11.2024 18:15:21
  • Zuletzt bearbeitet 05.06.2025 13:58:30

Weaver Ecology v9.* was discovered to contain a SQL injection vulnerability via the component /mobilemode/Action.jsp?invoker=com.weaver.formmodel.mobile.mec.servlet.MECAction&action=getFieldTriggerValue&searchField=*&fromTable=HrmResourceManager&wher...

  • EPSS 0.84%
  • Veröffentlicht 19.11.2024 17:15:09
  • Zuletzt bearbeitet 24.09.2025 19:08:16

E-cology has a directory traversal vulnerability. An attacker can exploit this vulnerability to delete the server directory, causing the server to permanently deny service.