On this page

Atomicorp WAF Rule 340159

Rule Summary

  • Rule ID: 340159
  • Status: Active
  • Alert message: Atomicorp.com WAF Rules: Generic SQL inline command protection (MM)
  • Observed CWEs: CWE-22 (1), CWE-74 (2), CWE-79 (2), CWE-89 (68), CWE-94 (1), CWE-184 (1), CWE-200 (1), CWE-284 (1), CWE-306 (1), CWE-697 (1)
  • Revision: 39
  • Rule severity: Critical (2)
  • Phase: 2 (request body)
  • Request surfaces: Request arguments, JSON request data, SOAP request data, XML request data
  • Rule action: deny
  • HTTP status: 403
  • Public tags: SQLi
  • Logging: log, auditlog

Description

This rule detects SQL content. It is tuned to try and ignore this in cases where this may be normal (SQL application for example). An example attack could be to get dump user passwords from a database:

union select from usernames

False Positives

Some applications use SQL in their arguments in ways that we may not have seen before, and therefore we have not tuned the rules to ignore this legitimate behavior. Some applications are vulnerable to SQL injection attacks and this may be an actual attack, and in some very bad cases an application may use raw SQL in an unprotected argument to function properly. Therefore a false positive can occur, and we recommend that you not disable this rule.

Instead, we recommend that you report this to use as a false positive. Our security team can determine if this is a legitimate case for you, or if its clever attack on your system and we will put out an update to the rules to make sure your application can function and that you are not opening your system to further attack. Instructions to report false positives are detailed on the Reporting False Positives wiki page.

If you wish to tune this rule yourself, please see the Tuning the Atomicorp WAF Rules page for basic information.

Similar Rules

WAF_340017

WAF_340016

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

CVEVulnerabilityProductCVSSSeverity
CVE-2014-8673SO Planning 1.32 - Multiple Vulnerabilitiessoplanning9.8 (v3.1)Critical
CVE-2015-3933GeniXCMS 0.0.3 - 'register.php' SQL Injectiongenixcms9.8 (v3.0)Critical
CVE-2016-10134Zabbix - SQL Injectionzabbix9.8 (v3.0)Critical
CVE-2017-17970Muviko 1.1 - SQL Injectionmuviko9.8 (v3.0)Critical
CVE-2017-8917Joomla! <3.7.1 - SQL Injectionjoomla!9.8 (v3.0)Critical
CVE-2018-11535Sitemakin SLAC 1.0 - 'my_item_search' SQL Injectionslac9.8 (v3.0)Critical
CVE-2019-12989Citrix SD-WAN and NetScaler SD-WAN - SQL Injectionnetscaler sd-wan9.8 (v3.1)Critical
CVE-2019-9762PHPSHE 1.7 - SQL Injectionphpshe9.8 (v3.0)Critical
CVE-2020-10546rConfig 3.9.4 - SQL Injectionrconfig9.8 (v3.1)Critical
CVE-2020-10547rConfig 3.9.4 - SQL Injectionrconfig9.8 (v3.1)Critical
CVE-2020-10548rConfig 3.9.4 - SQL Injectionrconfig9.8 (v3.1)Critical
CVE-2020-10549rConfig <=3.9.4 - SQL Injectionrconfig9.8 (v3.1)Critical
CVE-2020-12720vBulletin SQL Injectionvbulletin9.8 (v3.1)Critical
CVE-2020-20300WeiPHP 5.0 - SQL Injectionweiphp9.8 (v3.1)Critical
CVE-2020-2220874cms - ajax_street.php 'x' SQL Injection74cms9.8 (v3.1)Critical
CVE-2020-2221174cms - ajax_street.php 'key' SQL Injection74cms9.8 (v3.1)Critical
CVE-2020-8656EyesOfNetwork - Hardcoded API Key & SQL Injectioneyesofnetwork9.8 (v3.1)Critical
CVE-2021-24827WordPress Asgaros Forum <1.15.13 - SQL Injectionasgaros forum9.8 (v3.1)Critical
CVE-2021-25114WordPress Paid Memberships Pro <2.6.7 - Blind SQL Injectionpaid memberships pro9.8 (v3.1)Critical
CVE-2021-34187Chamilo model.ajax.php - SQL Injectionchamilo9.8 (v3.1)Critical
CVE-2021-41691openSIS Student Information System 8.0 SQL Injectionopensis9.8 (v3.1)Critical
CVE-2022-0412WordPress TI WooCommerce Wishlist <1.40.1 - SQL Injectionti woocommerce wishlist9.8 (v3.1)Critical
CVE-2022-0434WordPress Page Views Count <2.4.15 - SQL Injectionpage view count9.8 (v3.1)Critical
CVE-2022-23898MCMS 5.2.5 - SQL Injectionmcms9.8 (v3.1)Critical
CVE-2022-24260VoipMonitor - Pre-Auth SQL Injectionvoipmonitor9.8 (v3.1)Critical
CVE-2022-25125MCMS 5.2.4 - SQL Injectionmcms9.8 (v3.1)Critical
CVE-2022-25488Atom CMS v2.0 - SQL Injectionatomcms9.8 (v3.1)Critical
CVE-2022-31181PrestaShop - SQL Injection to Eval Injectionprestashop9.8 (v3.1)Critical
CVE-2023-0938Music Gallery Site v1.0 - SQL Injection on music_list.phpmusic gallery site9.8 (v3.1)Critical
CVE-2023-0961Music Gallery Site v1.0 - SQL Injection on page view_music_details.phpmusic gallery site9.8 (v3.1)Critical
CVE-2023-1454Jeecg-boot 3.5.0 qurestSql - SQL Injectionjeecg boot9.8 (v3.1)Critical
CVE-2024-24112Exrick XMall - SQL Injectionxmall9.8 (v3.1)Critical
CVE-2024-48307JeecgBoot v3.7.1 - SQL Injectionjeecg boot9.8 (v3.1)Critical
CVE-2024-6671WhatsUp Gold GetStatisticalMonitorList SQL Injection - Authentication Bypasswhatsup gold9.8 (v3.1)Critical
CVE-2025-29085Vipshop Saturn Console <= 3.5.1 - SQL Injection via ClusterKey Componentvipshop Saturn v.3.5.1 and before9.8 (v3.1)Critical
CVE-2025-32814NetMRI Unauthenticated SQL Injection via skipjackUsernamenetmri9.8 (v3.1)Critical
CVE-2024-32709WP-Recall <= 16.26.5 - SQL InjectionWP-Recall9.3 (v3.1)Critical
CVE-2025-32969XWiki REST API Query - SQL Injectionxwiki9.3 (v4.0)Critical
CVE-2025-52472XWiki - HQL Injectionxwiki9.3 (v4.0)Critical
CVE-2024-5217ServiceNow - Incomplete Input Validationservicenow9.2 (v4.0)Critical
CVE-2023-0903Employee Task Management System v1.0 - SQL Injection on edit-task.phpemployee task management system8.8 (v3.1)High
CVE-2023-0904Employee Task Management System v1.0 - SQL Injection on (task-details.php?task_id=?)employee task management system8.8 (v3.1)High
CVE-2023-0912Auto Dealer Management System v1.0 - SQL Injectionauto dealer management system8.8 (v3.1)High
CVE-2023-0913Auto Dealer Management System v1.0 - SQL Injection in sell_vehicle.phpauto dealer management system8.8 (v3.1)High
CVE-2023-0915Auto Dealer Management System v1.0 - SQL Injection on manage_user.phpauto dealer management system8.8 (v3.1)High
CVE-2023-0962Music Gallery Site v1.0 - SQL Injection on page Master.phpmusic gallery site8.8 (v3.1)High
CVE-2023-46022Blood Bank 1.0 - 'bid' SQLiblood bank7.8 (v3.1)High
CVE-2014-8675SO Planning 1.32 - Multiple Vulnerabilitiessoplanning7.5 (v3.0)High
CVE-2015-7297Joomla! Core SQL Injectionjoomla!7.5 (v2.0)High
CVE-2020-22165PHPGurukul Hospital Management System 4.0 - SQL Injectionhospital management system7.5 (v3.1)High
CVE-2021-41460ECShop 4.1.0 - SQL Injectionecshop7.5 (v3.1)High
CVE-2022-24264Cuppa CMS v1.0 - SQL injectioncuppacms7.5 (v3.1)High
CVE-2018-10735NagiosXI <= 5.4.12 commandline.php SQL injectionnagios xi7.2 (v3.0)High
CVE-2018-10736NagiosXI <= 5.4.12 - SQL injectionnagios xi7.2 (v3.0)High
CVE-2018-10738NagiosXI <= 5.4.12 menuaccess.php - SQL injectionnagios xi7.2 (v3.0)High
CVE-2019-17418MetInfo 7.0.0 beta - SQL Injectionmetinfo7.2 (v3.1)High
CVE-2022-31974Online Fire Reporting System v1.0 - SQL injectiononline fire reporting system7.2 (v3.1)High
CVE-2022-31975Online Fire Reporting System v1.0 - SQL injectiononline fire reporting system7.2 (v3.1)High
CVE-2022-32007Complete Online Job Search System 1.0 - SQL Injectioncomplete online job search system7.2 (v3.1)High
CVE-2022-32015Complete Online Job Search System 1.0 - SQL Injectioncomplete online job search system7.2 (v3.1)High
CVE-2022-32018Complete Online Job Search System 1.0 - SQL Injectioncomplete online job search system7.2 (v3.1)High
CVE-2022-32024Car Rental Management System 1.0 - SQL Injectioncar rental management system7.2 (v3.1)High
CVE-2022-32025Car Rental Management System 1.0 - SQL Injectioncar rental management system7.2 (v3.1)High
CVE-2022-32026Car Rental Management System 1.0 - SQL Injectioncar rental management system7.2 (v3.1)High
CVE-2022-32028Car Rental Management System 1.0 - SQL Injectioncar rental management system7.2 (v3.1)High
CVE-2023-33439Faculty Evaluation System v1.0 - SQL Injectionfaculty evaluation system7.2 (v3.1)High
CVE-2023-45826Leantime < 2.4 - Authenticated SQL Injectionleantime6.5 (v3.1)Medium
CVE-2024-5522WordPress HTML5 Video Player < 2.5.27 - SQL Injectionhtml5 video player6.5 (v3.1)Medium
CVE-2024-32231Stash < 0.26.0 - SQL Injectionstash6.3 (v3.1)Medium
CVE-2014-8674SO Planning 1.32 - Multiple Vulnerabilitiessoplanning5.4 (v3.1)Medium
CVE-2023-0902Employee Task Management System v1.0 - SQL Injection on edit-task.phpsimple food ordering system5.4 (v3.1)Medium
CVE-2014-8676SO Planning 1.32 - Multiple Vulnerabilitiessoplanning5.3 (v3.0)Medium
CVE-2014-8677SO Planning 1.32 - Multiple Vulnerabilitiessoplanning5.3 (v3.0)Medium
CVE-2025-10210ChanCMS <= 3.3.0 - SQL Injectionchancms2.1 (v4.0)Low

Observed CWEs

These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.

CWERelated Published CVEs
CWE-22CVE-2014-8676
CWE-74CVE-2022-31181 , CVE-2025-10210
CWE-79CVE-2014-8674 , CVE-2023-0902
CWE-89CVE-2014-8673 , CVE-2015-3933 , CVE-2016-10134 , CVE-2017-17970 , CVE-2017-8917 , CVE-2018-11535 , CVE-2019-12989 , CVE-2019-9762 , CVE-2020-10546 , CVE-2020-10547 , CVE-2020-10548 , CVE-2020-10549 , CVE-2020-12720 , CVE-2020-20300 , CVE-2020-22208 , CVE-2020-22211 , CVE-2020-8656 , CVE-2021-24827 , CVE-2021-25114 , CVE-2021-34187 , CVE-2021-41691 , CVE-2022-0412 , CVE-2022-0434 , CVE-2022-23898 , CVE-2022-24260 , CVE-2022-25125 , CVE-2022-25488 , CVE-2022-31181 , CVE-2023-0938 , CVE-2023-0961 , CVE-2023-1454 , CVE-2024-24112 , CVE-2024-48307 , CVE-2024-6671 , CVE-2025-29085 , CVE-2025-32814 , CVE-2024-32709 , CVE-2025-32969 , CVE-2025-52472 , CVE-2023-0903 , CVE-2023-0904 , CVE-2023-0912 , CVE-2023-0913 , CVE-2023-0915 , CVE-2023-0962 , CVE-2023-46022 , CVE-2015-7297 , CVE-2020-22165 , CVE-2021-41460 , CVE-2022-24264 , CVE-2018-10735 , CVE-2018-10736 , CVE-2018-10738 , CVE-2019-17418 , CVE-2022-31974 , CVE-2022-31975 , CVE-2022-32007 , CVE-2022-32015 , CVE-2022-32018 , CVE-2022-32024 , CVE-2022-32025 , CVE-2022-32026 , CVE-2022-32028 , CVE-2023-33439 , CVE-2023-45826 , CVE-2024-5522 , CVE-2024-32231 , CVE-2025-10210
CWE-94CVE-2014-8677
CWE-184CVE-2024-5217
CWE-200CVE-2014-8675
CWE-284CVE-2014-8677
CWE-306CVE-2020-12720
CWE-697CVE-2024-5217

Documentation Source

  • Original wiki page: WAF 340159
  • Source revision: 3776
  • Source revision date: 2013-07-30