OA E-Office Uploadify Arbitrary File Upload Scanner
Detects missing file type validation in E-Office's Uploadify endpoint, allowing attackers to upload malicious scripts and gain remote code execution.
Short Info
Level
Single Scan
Single Scan
Can be used by
Asset Owner
Estimated Time
10 seconds
Time Interval
1 month 13 hours
Scan only one
Domain, IPv4, Subdomain
Toolbox
E-Office is a comprehensive office automation platform used by organizations to streamline document management, workflow processes, and internal communications. It is widely adopted by administrative departments to enhance productivity and reduce manual paperwork. As a web-based solution, E-Office enables remote teams to collaborate efficiently, making it a critical component of modern business operations.
The Arbitrary File Upload vulnerability arises when the Uploadify component fails to validate file types or enforce access controls. This allows attackers to bypass security checks and upload executable files such as PHP or ASP scripts. The flaw typically stems from insufficient server-side validation and misconfigured upload handlers.
Specifically, the vulnerability targets the Uploadify endpoint within E-Office, where file upload requests are processed without proper MIME type or extension filtering. Attackers can craft HTTP requests to upload malicious files directly to the server, often using tools like Burp Suite or custom scripts. The lack of authentication checks on this endpoint further exacerbates the risk.
If exploited, this vulnerability can lead to full server compromise, data theft, or malware deployment. Attackers can execute arbitrary commands, access sensitive documents, or pivot to internal networks. Given the CVSS score of 9.0, immediate remediation is critical to prevent severe business disruption and data breaches.