OA E-Office Uploadify Arbitrary File Upload Scanner

Detects missing file type validation in E-Office's Uploadify endpoint, allowing attackers to upload malicious scripts and gain remote code execution.

Short Info


Level

Critical

Single Scan

Single Scan

Can be used by

Asset Owner

Estimated Time

10 seconds

Time Interval

1 month 13 hours

Scan only one

Domain, IPv4, Subdomain

Toolbox

E-Office is a comprehensive office automation platform used by organizations to streamline document management, workflow processes, and internal communications. It is widely adopted by administrative departments to enhance productivity and reduce manual paperwork. As a web-based solution, E-Office enables remote teams to collaborate efficiently, making it a critical component of modern business operations.

The Arbitrary File Upload vulnerability arises when the Uploadify component fails to validate file types or enforce access controls. This allows attackers to bypass security checks and upload executable files such as PHP or ASP scripts. The flaw typically stems from insufficient server-side validation and misconfigured upload handlers.

Specifically, the vulnerability targets the Uploadify endpoint within E-Office, where file upload requests are processed without proper MIME type or extension filtering. Attackers can craft HTTP requests to upload malicious files directly to the server, often using tools like Burp Suite or custom scripts. The lack of authentication checks on this endpoint further exacerbates the risk.

If exploited, this vulnerability can lead to full server compromise, data theft, or malware deployment. Attackers can execute arbitrary commands, access sensitive documents, or pivot to internal networks. Given the CVSS score of 9.0, immediate remediation is critical to prevent severe business disruption and data breaches.

Get started to protecting your digital assets