On this page
Atomicorp WAF Rule 344362
Rule Summary
- Rule ID: 344362
- Status: Active
- Alert message: Atomicorp.com WAF Rules: Remote Command Execution: Unix Command Injection (2-3 chars)
- Observed CWEs: CWE-20 (4), CWE-22 (3), CWE-73 (1), CWE-74 (3), CWE-77 (1), CWE-78 (5), CWE-79 (2), CWE-89 (6), CWE-94 (3), CWE-158 (1), CWE-287 (2), CWE-306 (2), CWE-352 (3), CWE-502 (11), CWE-798 (1), CWE-918 (5)
- Revision: 2
- Rule severity: Critical (2)
- Phase: 2 (request body)
- Request surfaces: Request cookies, Request argument names, Request arguments, JSON request data, SOAP request data, XML request data
- Rule action: deny
- HTTP status: 403
- Logging: log, auditlog
Description
This rule detects behavior identified by its current alert as “Remote Command Execution: Unix Command Injection (2-3 chars)” in the request cookies, request argument names, request arguments, JSON request data, SOAP request data, XML request data. It evaluates during the request body phase and denies matching traffic with HTTP status 403.
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
| CVE | Vulnerability | Product | CVSS | Severity |
|---|---|---|---|---|
| CVE-2019-16932 | Visualizer <3.3.1 - Blind Server-Side Request Forgery | visualizer | 10.0 (v3.1) | Critical |
| CVE-2025-47812 | Wing FTP Server <= 7.4.3 - Remote Code Execution | wftpserver | 10.0 (v3.1) | Critical |
| CVE-2026-44182 | Jupyter Enterprise Gateway Has Kubernetes Manifest Injection via Jinja2 Template Rendering | enterprise gateway | 10.0 (v4.0) | Critical |
| CVE-2026-8985 | Unauthenticated Command Injection | maxicharger single charger firmware | 10.0 (v4.0) | Critical |
| CVE-2026-34838 | Group-Office: Authenticated Remote Code Execution via PHP Insecure Deserialization in AbstractSettingsCollection | group-office | 9.9 (v3.1) | Critical |
| CVE-2017-12611 | Apache Struts2 S2-053 - Remote Code Execution | struts | 9.8 (v3.0) | Critical |
| CVE-2018-17431 | Comodo Unified Threat Management Web Console - Remote Code Execution | unified threat management firewall | 9.8 (v3.1) | Critical |
| CVE-2019-1935 | Cisco UCS Director_ Cisco Integrated Management Controller Supervisor and Cisco UCS Director Express for Big Data - Multiple Vulnerabilities | integrated management controller supervisor | 9.8 (v3.1) | Critical |
| CVE-2019-1937 | Cisco UCS Director_ Cisco Integrated Management Controller Supervisor and Cisco UCS Director Express for Big Data - Multiple Vulnerabilities | integrated management controller supervisor | 9.8 (v3.0) | Critical |
| CVE-2019-5434 | Revive Adserver 4.2 - Remote Code Execution | revive adserver | 9.8 (v3.0) | Critical |
| CVE-2020-14750 | Oracle WebLogic Server - Remote Command Execution | fusion middleware | 9.8 (v3.1) | Critical |
| CVE-2021-22175 | GitLab CI Lint API - Server-Side Request Forgery | gitlab | 9.8 (v3.1) | Critical |
| CVE-2021-42237 | Sitecore Experience Platform Pre-Auth RCE | experience platform | 9.8 (v3.1) | Critical |
| CVE-2022-31181 | PrestaShop - SQL Injection to Eval Injection | prestashop | 9.8 (v3.1) | Critical |
| CVE-2023-40504 | LG Simple Editor <= v3.21.0 - Command Injection | simple editor | 9.8 (v3.1) | Critical |
| CVE-2024-0986 | Issabel Authenticated - Remote Code Execution | pbx | 9.8 (v3.1) | Critical |
| CVE-2024-6670 | WhatsUp Gold HasErrors SQL Injection - Authentication Bypass | whatsup gold | 9.8 (v3.1) | Critical |
| CVE-2024-6671 | WhatsUp Gold GetStatisticalMonitorList SQL Injection - Authentication Bypass | whatsup gold | 9.8 (v3.1) | Critical |
| CVE-2026-19912 | Kaltura HTML5 Video Player, html5 library Arbitrary Code Execution Vulnerability | Kaltura HTML5 Video Player, html5 library | 9.8 (v3.1) | Critical |
| CVE-2026-8986 | Command Injection via Malicious OCPP Server | maxicharger single charger firmware | 9.5 (v4.0) | Critical |
| CVE-2026-42596 | Gotenberg < 8.31.0 - Server-Side Request Forgery | gotenberg | 9.4 (v3.1) | Critical |
| CVE-2013-2642 | Sophos Web Protection Appliance 3.7.8.1 - Multiple Vulnerabilities | web appliance firmware | 9.3 (v2.0) | High |
| CVE-2026-10042 | manga-image-translator RCE via Unsafe Pickle Deserialization in Share Model | manga-image-translator | 9.2 (v4.0) | Critical |
| CVE-2026-87930 | MaxSite CMS through 109.6 PHP Object Injection via ci_session | MaxSite CMS | 9.2 (v4.0) | Critical |
| CVE-2023-36934 | MOVEit Transfer - SQL Injection | moveit transfer | 9.1 (v3.1) | Critical |
| CVE-2026-14602 | Remote API <= 0.2 - Unauthenticated PHP Object Injection via remote-api Query Parameter | Remote API | 9.0 (v3.1) | Critical |
| CVE-2018-11442 | EasyService Billing 1.0 - Cross-Site Request Forgery | easyservice billing | 8.8 (v3.0) | High |
| CVE-2018-11445 | EasyService Billing 1.0 - Cross-Site Request Forgery | easyservice billing | 8.8 (v3.0) | High |
| CVE-2019-15642 | Webmin < 1.920 - Authenticated Remote Code Execution | webmin | 8.8 (v3.0) | High |
| CVE-2022-41800 | F5 BIG-IP Appliance Mode - Command Injection | big-ip access policy manager | 8.7 (v3.1) | High |
| CVE-2025-71260 | BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 VIEWSTATE Deserialization RCE | footprints | 8.7 (v4.0) | High |
| CVE-2026-47722 | nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml | nebula-mesh | 8.7 (v4.0) | High |
| CVE-2026-71981 | Cypht < 2.12.2 PHP Object Injection RCE via back_query Parameter | cypht | 8.7 (v4.0) | High |
| CVE-2021-22214 | Gitlab CE/EE 10.5 - Server-Side Request Forgery | gitlab | 8.6 (v3.1) | High |
| CVE-2018-1000130 | Jolokia Agent - JNDI Code Injection | webarchive agent | 8.1 (v3.0) | High |
| CVE-2026-40280 | Gotenberg <= 8.30.1 - Server Side Request Forgery | gotenberg | 7.8 (v4.0) | High |
| CVE-2011-4448 | WikkaWiki 1.3.2 - Multiple Vulnerabilities | wikkawiki | 7.5 (v2.0) | High |
| CVE-2017-10271 | Oracle WebLogic Server - Remote Command Execution | weblogic server | 7.5 (v3.1) | High |
| CVE-2026-12720 | Kirki < 6.0.13 - Unauthenticated PHP Object Injection | Kirki | 7.5 (v3.1) | High |
| CVE-2026-19913 | Kaltura HTML5 Video Player, html5lib library Improper Input Validation Vulnerability | Kaltura HTML5 Video Player, html5lib library | 7.5 (v3.1) | High |
| CVE-2026-61686 | SolidInvoice: PHP unserialize() called on client-controlled data in DataGrid LiveComponent context prop | SolidInvoice | 7.5 (v3.1) | High |
| CVE-2019-1936 | Cisco UCS Director_ Cisco Integrated Management Controller Supervisor and Cisco UCS Director Express for Big Data - Multiple Vulnerabilities | integrated management controller supervisor | 7.2 (v3.1) | High |
| CVE-2025-71257 | BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication Bypass | footprints itsm | 6.9 (v4.0) | Medium |
| CVE-2011-4449 | WikkaWiki 1.3.2 - Multiple Vulnerabilities | wikkawiki | 6.8 (v2.0) | Medium |
| CVE-2011-4452 | WikkaWiki 1.3.2 - Multiple Vulnerabilities | wikkawiki | 6.8 (v2.0) | Medium |
| CVE-2011-4450 | WikkaWiki 1.3.2 - Multiple Vulnerabilities | wikkawiki | 6.4 (v2.0) | Medium |
| CVE-2024-32231 | Stash < 0.26.0 - SQL Injection | stash | 6.3 (v3.1) | Medium |
| CVE-2025-48954 | Discourse OAuth Social Login - Cross-site Scripting | discourse | 6.1 (v3.1) | Medium |
| CVE-2013-2641 | Sophos Web Protection Appliance 3.7.8.1 - Multiple Vulnerabilities | web appliance firmware | 5.0 (v2.0) | Medium |
| CVE-2011-4451 | WikkaWiki 1.3.2 - Multiple Vulnerabilities | wikkawiki | 4.3 (v2.0) | Medium |
| CVE-2013-2643 | Sophos Web Protection Appliance 3.7.8.1 - Multiple Vulnerabilities | web appliance firmware | 4.3 (v2.0) | Medium |
| CVE-2026-16297 | Clearfy < 2.4.3 - Admin+ PHP Object Injection via Settings Import | Clearfy Cache | 4.1 (v3.1) | Medium |
| CVE-2023-3360 | Weaver Show Posts < 1.8.1 - Admin+ PHP Object Injection | Weaver Show Posts | 3.3 (v3.1) | Low |
Observed CWEs
These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.