Weaver Network Co., Ltd. Vulnerabilities and Affected Products
Vulnerabilities associated with E-cology 8.0.
Products
Clear product- E-cology2 vulnerabilities
- E-cology 8.02 vulnerabilities
- E-cology 9.02 vulnerabilities
- E-office1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-50997HIGH | Weaver E-cology 8.0 / 9.0 SQL Injection via HrmCareerApplyPerView.jspWeaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in the HrmCareerApplyPerView.jsp endpoint that allows unauthenticated remote attackers to extract arbitrary data from the backend database by manipulating the id GET parameter. Attackers can send a single crafted GET request with UNION-based injection payloads through the unsanitized id parameter to retrieve arbitrary data from the Microsoft SQL Server backend. This vulnerability is potentially remediated in software ver… CWE-89Aug 11, 2026 | CVSS8.7v4.0 | EPSS0.462% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2016-20097HIGH | Weaver E-cology 8.0 SQL Injection File Read via SignatureDownLoadWeaver (Fanwei) E-cology 8.0 contains a SQL injection vulnerability in the SignatureDownLoad servlet that allows unauthenticated remote attackers to read arbitrary files by injecting a UNION SELECT payload into the markId GET parameter, which is concatenated unsanitized into a SQL query. Attackers can control the markPath value returned by the query to supply an attacker-controlled filesystem path, causing the servlet to read and stream back arbitrary files accessible to the application server p… CWE-89Aug 11, 2026 | CVSS8.7v4.0 | EPSS0.47% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |