Showing 2 vulnerabilities on this page for E-cology 8.0

Signals CISA KEV Ransomware Nuclei
Weaver Network Co., Ltd. vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Weaver E-cology 8.0 / 9.0 SQL Injection via HrmCareerApplyPerView.jsp

Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in the HrmCareerApplyPerView.jsp endpoint that allows unauthenticated remote attackers to extract arbitrary data from the backend database by manipulating the id GET parameter. Attackers can send a single crafted GET request with UNION-based injection payloads through the unsanitized id parameter to retrieve arbitrary data from the Microsoft SQL Server backend. This vulnerability is potentially remediated in software ver

CWE-89Aug 11, 2026
CVSS8.7v4.0EPSS0.462%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Weaver E-cology 8.0 SQL Injection File Read via SignatureDownLoad

Weaver (Fanwei) E-cology 8.0 contains a SQL injection vulnerability in the SignatureDownLoad servlet that allows unauthenticated remote attackers to read arbitrary files by injecting a UNION SELECT payload into the markId GET parameter, which is concatenated unsanitized into a SQL query. Attackers can control the markPath value returned by the query to supply an attacker-controlled filesystem path, causing the servlet to read and stream back arbitrary files accessible to the application server p

CWE-89Aug 11, 2026
CVSS8.7v4.0EPSS0.47%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX