Weaver E-cology 存在一个无需身份验证的 SQL 注入漏洞,远程攻击者可通过在移动插件端点的 GET 参数中提交恶意输入,执行任意 SQL 查询。攻击者可通过将 SQL 关键词用括号包裹来绕过基于空格的过滤控制,实施 UNION 型注入,从而从数据库中提取敏感数据,包括管理员账户的凭证哈希值。该漏洞利用的首次证据由 Shadowserver 基金会于 2022-07-28 观察到。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Weaver Network Co., Ltd. | E-cology | * |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Weaver Network Co., Ltd. | E-cology | * | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet