On this page

Atomicorp WAF Rule 340155

Rule Summary

  • Rule ID: 340155
  • Status: Active
  • Alert message: Atomicorp.com WAF Rules: Generic SQL Injection protection
  • Observed CWEs: CWE-22 (1), CWE-79 (1), CWE-89 (14), CWE-94 (1), CWE-200 (1), CWE-284 (1), CWE-306 (1), CWE-1336 (1)
  • Revision: 25
  • Rule severity: Critical (2)
  • Phase: 2 (request body)
  • Request surfaces: Request headers, Request cookies, Request arguments, JSON request data, SOAP request data, XML request data
  • Rule action: deny
  • HTTP status: 403
  • Public tags: SQLi
  • Logging: log, auditlog

Description

This rule detects SQL injection attacks. If this rule is being triggered, this means that someone has attempted to inject a SQL statement into an application.

Troubleshooting

False Positives

If you believe this is a false positive, please report this to our security team to determine if this is a legitimate case, or if its clever attack on your system. Instructions to report false positives are detailed on the Reporting False Positives wiki page. If it is a false positive, we will fix the issue in the rules and get a release out to you promptly.

Tuning Guidance

If you want to disable this rule, please see the Tuning the Atomicorp WAF Rules page for basic information.

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

CVEVulnerabilityProductCVSSSeverity
CVE-2014-8673SO Planning 1.32 - Multiple Vulnerabilitiessoplanning9.8 (v3.1)Critical
CVE-2015-3933GeniXCMS 0.0.3 - 'register.php' SQL Injectiongenixcms9.8 (v3.0)Critical
CVE-2018-11535Sitemakin SLAC 1.0 - 'my_item_search' SQL Injectionslac9.8 (v3.0)Critical
CVE-2018-18755K-iwi Framework 1775 - SQL Injectionk-iwi9.8 (v3.1)Critical
CVE-2018-18761SaltOS Erp Crm 3.1 r8126 - SQL Injectionsaltos9.8 (v3.1)Critical
CVE-2019-10232Teclib GLPI <= 9.3.3 - Unauthenticated SQL Injectiongestionnaire libre de parc informatique9.8 (v3.0)Critical
CVE-2020-12720vBulletin SQL Injectionvbulletin9.8 (v3.1)Critical
CVE-2020-13640wpDiscuz <= 5.3.5 - SQL Injectionwpdiscuz9.8 (v3.1)Critical
CVE-2025-51683mJobTime <= 15.7.2 - Unauthenticated Blind SQL Injection to RCEmjobtime9.8 (v3.1)Critical
CVE-2026-28496FOSSBilling - Server-Side Template InjectionFOSSBilling9.4 (v4.0)Critical
CVE-2019-13462Lansweeper Unauthenticated SQL Injectionlansweeper9.1 (v3.0)Critical
CVE-2024-29824Ivanti EPM - Remote Code Executionendpoint manager8.8 (v3.1)High
CVE-2014-8675SO Planning 1.32 - Multiple Vulnerabilitiessoplanning7.5 (v3.0)High
CVE-2018-10737NagiosXI <= 5.4.12 logbook.php SQL injectionnagios xi7.2 (v3.0)High
CVE-2018-10738NagiosXI <= 5.4.12 menuaccess.php - SQL injectionnagios xi7.2 (v3.0)High
CVE-2014-8674SO Planning 1.32 - Multiple Vulnerabilitiessoplanning5.4 (v3.1)Medium
CVE-2014-8676SO Planning 1.32 - Multiple Vulnerabilitiessoplanning5.3 (v3.0)Medium
CVE-2014-8677SO Planning 1.32 - Multiple Vulnerabilitiessoplanning5.3 (v3.0)Medium
CVE-2025-22214Landray EIS SQL注入漏洞-4.3 (v3.1)Medium

Observed CWEs

These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.

CWERelated Published CVEs
CWE-22CVE-2014-8676
CWE-79CVE-2014-8674
CWE-89CVE-2014-8673 , CVE-2015-3933 , CVE-2018-11535 , CVE-2018-18755 , CVE-2018-18761 , CVE-2019-10232 , CVE-2020-12720 , CVE-2020-13640 , CVE-2025-51683 , CVE-2019-13462 , CVE-2024-29824 , CVE-2018-10737 , CVE-2018-10738 , CVE-2025-22214
CWE-94CVE-2014-8677
CWE-200CVE-2014-8675
CWE-284CVE-2014-8677
CWE-306CVE-2020-12720
CWE-1336CVE-2026-28496

Documentation Source

  • Original wiki page: WAF 340155
  • Source revision: 5570
  • Source revision date: 2015-09-26