References https://github.com/AboSteam/POPC/blob/main/%E6%B3%9B%E5%BE%AEe-cology%E6%8E%A5%E5%8F%A3getLabelByModule%E5%AD%98%E5%9C%A8sql%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://blog.csdn.net/weixin_43567873/article/details/137908375 https://cn-sec.com/archives/2402180.html https://ddpoc.com/DVB-2025-10127.html https://blog.csdn.net/weixin_43167326/article/details/135713711 https://github.com/ax1sX/SecurityList/blob/main/Java_OA/EcologyAudit.md
Related VulnerabilitiesPoCecology-execforstr-rce: Weaver Ecology ExecForStr Remote Command ExecutionPoCweaver-ecology9-doc-list-sqli: Weaver E-cology9 api/doc/out/more/list SQL InjectionPoCweaver-getemdslist-disclosure: Weaver E-cology getEmDsList Sensitive Information DisclosureSAP Netweaver 未授权 反序列化漏洞泛微OA weaver.common.Ctrl 任意文件上传漏洞e-weaver-eoffice-webservice-upload-fileupload: E-Weaver EOffice webservice upload file uploadweaver-oa-workrelate-file-upload: Weaver OA Workrelate File Upload泛微OA /weaver/weaver.file.FileDownloadForOutDoc SQL 注入漏洞PoCCVE-2016-2389: SAP xMII 15.0 for SAP NetWeaver 7.4 - Local File InclusionPoCCVE-2017-12637: SAP NetWeaver Application Server Java 7.5 - Local File InclusionPoCCVE-2020-6287: SAP NetWeaver AS JAVA 7.30-7.50 - Remote Admin AdditionPoCCVE-2021-33690: SAP NetWeaver Development Infrastructure - Server Side Request Forgery