Weaver E-cology是中国泛微(Weaver)公司的一个协同管理平台。 Weaver E-cology 9.5 10.52之前版本存在路径遍历漏洞,该漏洞源于XmlRpcServlet接口的XML-RPC端点存在任意文件读取漏洞,允许未经身份验证的远程攻击者通过向WorkflowService.getAttachment和WorkflowService.LoadTemplateProp方法提供文件路径来读取任意文件,包括系统配置文件和数据库凭据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Weaver Network Co., Ltd. | E-cology | < 10.52 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Weaver Network Co., Ltd. | E-cology | 0 ~ 10.52 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet