漏洞描述 【漏洞对象】E-Weaver泛微协同办公系统 【漏洞描述】E-Weaver泛微协同办公系统E-mobile/calendar_page.php文件的detailid参数存在SQL注入,可造成数据泄露,甚至服务器被入侵。
相关漏洞推荐 e-weaver-eoffice-webservice-upload-fileupload: E-Weaver EOffice webservice upload file upload weaver-oa-workrelate-file-upload: Weaver OA Workrelate File Upload POC CVE-2016-2389: SAP xMII 15.0 for SAP NetWeaver 7.4 - Local File Inclusion POC CVE-2017-12637: SAP NetWeaver Application Server Java 7.5 - Local File Inclusion POC CVE-2020-6287: SAP NetWeaver AS JAVA 7.30-7.50 - Remote Admin Addition POC CVE-2021-33690: SAP NetWeaver Development Infrastructure - Server Side Request Forgery POC CVE-2023-2648: Weaver E-Office 9.5 - Remote Code Execution POC CVE-2023-2766: Weaver OA 9.5 - Information Disclosure POC CVE-2025-31324: SAP NetWeaver Visual Composer Metadata Uploader - Deserialization POC CNVD-2022-43245: Weaver OA XmlRpcServlet - Arbitary File Read POC CVE-2023-2766: Weaver OA 9.5 - Information Disclosure POC e-cology-oa-e-weaver-signature-download: 泛微 OA E-Weaver SignatureDownLoad 任意文件读取 POC weaver-ebridge-addTasteJsonp-sqli: Weaver e-Bridge addTasteJsonp SQL Injection