Showing 2 vulnerabilities on this page for E-cology 9.0

Signals CISA KEV Ransomware Nuclei
Weaver Network Co., Ltd. vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Weaver E-cology 8.0 / 9.0 SQL Injection via HrmCareerApplyPerView.jsp

Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in the HrmCareerApplyPerView.jsp endpoint that allows unauthenticated remote attackers to extract arbitrary data from the backend database by manipulating the id GET parameter. Attackers can send a single crafted GET request with UNION-based injection payloads through the unsanitized id parameter to retrieve arbitrary data from the Microsoft SQL Server backend. This vulnerability is potentially remediated in software ver

CWE-89Aug 11, 2026
CVSS8.7v4.0EPSS0.462%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Weaver E-cology 9.0 File Upload RCE via uploaderOperate.jsp

Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to upload arbitrary files, including JSP webshells, by submitting a multipart/form-data POST request to /workrelate/plan/util/uploaderOperate.jsp with arbitrary secId and plandetailid field values. Successful exploitation results in remote code execution under the privileges of the application server process. Exploitation evidence was first observed by the Shado

CWE-434Aug 7, 2026
CVSS9.3v4.0EPSS0.687%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX