On this page
Atomicorp WAF Rule 340003
Rule Summary
- Rule ID: 340003
- Status: Active
- Alert message: Atomicorp.com WAF Rules: XSS attack in request headers
- Observed CWEs: CWE-79 (12), CWE-83 (1), CWE-89 (1), CWE-287 (1)
- Revision: 10
- Rule severity: Critical (2)
- Phase: 2 (request body)
- Request surfaces: Request URI, Request headers
- Rule action: deny
- HTTP status: 403
- Logging: log, auditlog
Description
Cross Site Scripting attack detected in the request headers.
False Positives
There are no known False Positives for this.
If you believe this is a false positive, it is recommended that you report this to our security team can determine if this is a legitimate case, or if its clever attack on your system. Instructions to report false positives are detailed on the Reporting False Positives wiki page.
Similar Rules
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
| CVE | Vulnerability | Product | CVSS | Severity |
|---|---|---|---|---|
| CVE-2012-1259 | Scrutinizer NetFlow & sFlow Analyzer - Multiple Vulnerabilities | scrutinizer netflow & sflow analyzer | 9.8 (v3.1) | Critical |
| CVE-2026-45118 | MyBB: Contact page reflected XSS | mybb | 9.3 (v3.1) | Critical |
| CVE-2026-12592 | SlimStat Analytics < 5.5.0 - Unauthenticated Stored XSS via CF-IPCountry Header | SlimStat Analytics | 7.5 (v3.1) | High |
| CVE-2012-1258 | Scrutinizer NetFlow & sFlow Analyzer - Multiple Vulnerabilities | scrutinizer netflow & sflow analyzer | 6.5 (v3.1) | Medium |
| CVE-2012-1260 | Scrutinizer NetFlow & sFlow Analyzer - Multiple Vulnerabilities | scrutinizer netflow & sflow analyzer | 6.1 (v3.1) | Medium |
| CVE-2012-1261 | Scrutinizer NetFlow & sFlow Analyzer - Multiple Vulnerabilities | scrutinizer netflow & sflow analyzer | 6.1 (v3.1) | Medium |
| CVE-2019-9591 | ShoreTel Connect ONSITE < 19.49.1500.0 - Multiple Vulnerabilities | connect onsite | 6.1 (v3.1) | Medium |
| CVE-2019-9592 | ShoreTel Connect ONSITE < 19.49.1500.0 - Multiple Vulnerabilities | connect onsite | 6.1 (v3.1) | Medium |
| CVE-2019-9593 | ShoreTel Connect ONSITE < 19.49.1500.0 - Multiple Vulnerabilities | connect onsite | 6.1 (v3.1) | Medium |
| CVE-2020-35416 | PHPJabbers Appointment Scheduler 2.3 - Reflected XSS (Cross-Site Scripting) | phpjabbers appointment scheduler | 6.1 (v3.1) | Medium |
| CVE-2022-33119 | NUUO NVRsolo Video Recorder 03.06.02 - Cross-Site Scripting | nvrsolo firmware | 6.1 (v3.1) | Medium |
| CVE-2020-20285 | ZZcms - Cross-Site Scripting | zzcms | 5.4 (v3.1) | Medium |
| CVE-2020-7108 | WordPress Plugin LearnDash LMS 3.1.2 - Reflective Cross-Site Scripting | learndash | 5.4 (v3.1) | Medium |
| CVE-2026-82451 | Formwork through 2.3.14 Stored XSS via Referer Header | Formwork | 5.3 (v4.0) | Medium |
| CVE-2025-41228 | VMware vSphere Client 8.0.3.0 - Reflected Cross-Site Scripting (XSS) | vCenter Server | 4.3 (v3.1) | Medium |
Observed CWEs
These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.
| CWE | Related Published CVEs |
|---|---|
| CWE-79 | CVE-2026-12592 , CVE-2012-1260 , CVE-2012-1261 , CVE-2019-9591 , CVE-2019-9592 , CVE-2019-9593 , CVE-2020-35416 , CVE-2022-33119 , CVE-2020-20285 , CVE-2020-7108 , CVE-2026-82451 , CVE-2025-41228 |
| CWE-83 | CVE-2026-45118 |
| CWE-89 | CVE-2012-1259 |
| CWE-287 | CVE-2012-1258 |
Documentation Source
- Original wiki page: WAF 340003
- Source revision: 702
- Source revision date: 2009-11-26