{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/cve-2016-20097/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2016-20097"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["E-cology 8.0"],"_cs_severities":["high"],"_cs_tags":["cve-2016-20097","sql-injection","webserver"],"_cs_type":"threat","_cs_vendors":["Weaver"],"content_html":"\u003cp\u003eWeaver (Fanwei) E-cology 8.0 contains a critical SQL injection vulnerability in the SignatureDownLoad servlet. The vulnerability originates from the unsanitized concatenation of the markId GET parameter into a SQL query. An unauthenticated remote attacker can supply a specially crafted UNION SELECT payload via the markId parameter to manipulate the query results. By controlling the markPath value returned by the database, the attacker can force the application to read and stream arbitrary files from the server's filesystem. This allows for the exfiltration of sensitive application configuration files, including those that store database credentials. This vulnerability has been subject to in-the-wild exploitation, with activity observed by the Shadowserver Foundation as early as October 18, 2023. Due to the lack of clear versioning for remediation, all instances of E-cology 8.0 should be treated as potentially vulnerable.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to read sensitive files from the server filesystem, leading to full application compromise, credential theft, and potentially remote code execution if configuration files or environment variables are leveraged. This poses a significant risk to organizations using the Weaver E-cology platform for business process management.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify and inventory all internet-facing instances of Weaver E-cology 8.0.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule below to monitor for SQL injection attempts against the SignatureDownLoad servlet.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the SignatureDownLoad servlet using a Web Application Firewall (WAF) or equivalent access control list.\u003c/li\u003e\n\u003cli\u003eConsult with Weaver vendor support to verify if the deployment has been patched against CVE-2016-20097.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-11T21:49:59Z","date_published":"2026-08-11T21:49:59Z","id":"https://feed.craftedsignal.io/briefs/2026-08-weaver-sql-injection/","summary":"Weaver E-cology 8.0 contains a SQL injection vulnerability in the SignatureDownLoad servlet that allows unauthenticated remote attackers to read arbitrary files via the markId parameter.","title":"SQL Injection in Weaver E-cology 8.0","url":"https://feed.craftedsignal.io/briefs/2026-08-weaver-sql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2016-20097","version":"https://jsonfeed.org/version/1.1"}