Vendor
Unauthenticated SQL Injection in Weaver E-cology
1 rule 2 TTPs 1 CVEWeaver E-cology is vulnerable to an unauthenticated SQL injection via the 'userIdentifiers' GET parameter, allowing attackers to extract sensitive database information including administrator credentials.
SQL Injection in Weaver E-cology 8.0
1 rule 1 TTP 1 CVEWeaver E-cology 8.0 contains a SQL injection vulnerability in the SignatureDownLoad servlet that allows unauthenticated remote attackers to read arbitrary files via the markId parameter.
Unauthenticated Remote Code Execution in Weaver E-cology 9.0
1 rule 1 TTP 1 CVEWeaver E-cology 9.0 versions prior to 10.52 are vulnerable to unauthenticated arbitrary file upload via the /workrelate/plan/util/uploaderOperate.jsp endpoint, allowing remote code execution.
Weaver E-cology Unauthenticated RCE Exploitation
2 rules 2 TTPs 1 CVEA critical unauthenticated remote code execution vulnerability (CVE-2026-22679) in Weaver E-cology office automation software is being actively exploited to execute system commands and reconnaissance activities on affected servers.
Weaver E-office Unauthenticated Arbitrary File Upload Vulnerability
2 rules 2 TTPs 1 CVEWeaver E-office versions prior to 10.0_20221201 are vulnerable to unauthenticated arbitrary file upload in the OfficeServer.php endpoint, allowing attackers to upload PHP webshells and achieve remote code execution.