NVD HIGH: CVE-2016-20097 — Weaver (Fanwei) E-cology 8.0 contains a SQL injection vulnerability in the Signa...
Weaver (Fanwei) E-cology 8.0 contains a SQL injection vulnerability in the SignatureDownLoad servlet that allows unauthenticated remote attackers to read arbitrary files by injecting a UNION SELECT payload into the markId GET parameter, which is concatenated unsanitized into a SQL query. Attackers can control the markPath value returned by the query to supply an attacker-controlled filesystem path
CVE-2016-20097