On this page
Atomicorp WAF Rule 344365
Rule Summary
- Rule ID: 344365
- Status: Active
- Alert message: Atomicorp.com WAF Rules: Possible Command Injection using abnormal escape
- Observed CWEs: CWE-20 (5), CWE-22 (24), CWE-29 (2), CWE-73 (1), CWE-78 (1), CWE-79 (4), CWE-89 (3), CWE-94 (8), CWE-200 (5), CWE-285 (1), CWE-287 (1), CWE-288 (1), CWE-305 (1), CWE-306 (2), CWE-326 (2), CWE-345 (2), CWE-352 (1), CWE-416 (2), CWE-434 (2), CWE-502 (12), CWE-552 (2), CWE-601 (46), CWE-602 (1), CWE-791 (1), CWE-829 (1)
- Revision: 2
- Rule severity: Critical (2)
- Phase: 2 (request body)
- Request surfaces: Request URI, Request headers, Request argument names, Request arguments, JSON request data, SOAP request data
- Rule action: deny
- HTTP status: 403
- Logging: log, auditlog
Description
This rule detects behavior identified by its current alert as “Possible Command Injection using abnormal escape” in the request URI, request headers, request argument names, request arguments, JSON request data, SOAP request data. It evaluates during the request body phase and denies matching traffic with HTTP status 403.
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
| CVE | Vulnerability | Product | CVSS | Severity |
|---|---|---|---|---|
| CVE-2025-32432 | CraftCMS - Remote Code Execution | craftcms | 10.0 (v3.1) | Critical |
| CVE-2025-57819 | FreePBX - Remote Code Execution | freepbx | 10.0 (v4.0) | Critical |
| CVE-2026-34838 | Group-Office: Authenticated Remote Code Execution via PHP Insecure Deserialization in AbstractSettingsCollection | group-office | 9.9 (v3.1) | Critical |
| CVE-2015-3933 | GeniXCMS 0.0.3 - 'register.php' SQL Injection | genixcms | 9.8 (v3.0) | Critical |
| CVE-2015-6834 | Kerio Control Unified Threat Management 9.1.0 build 1087/9.1.1 build 1324 - Multiple Vulnerabilities | php | 9.8 (v3.0) | Critical |
| CVE-2016-5771 | Kerio Control Unified Threat Management 9.1.0 build 1087/9.1.1 build 1324 - Multiple Vulnerabilities | php | 9.8 (v3.1) | Critical |
| CVE-2016-5773 | Kerio Control Unified Threat Management 9.1.0 build 1087/9.1.1 build 1324 - Multiple Vulnerabilities | php | 9.8 (v3.0) | Critical |
| CVE-2019-16920 | D-Link Routers - Remote Code Execution | dir-655 firmware | 9.8 (v3.1) | Critical |
| CVE-2019-5434 | Revive Adserver 4.2 - Remote Code Execution | revive adserver | 9.8 (v3.0) | Critical |
| CVE-2020-10189 | ManageEngine Desktop Central Java Deserialization | manageengine desktop central | 9.8 (v3.1) | Critical |
| CVE-2021-30118 | Kaseya VSA < 9.5.7 - Arbitrary File Upload to Remote Code Execution | vsa | 9.8 (v3.1) | Critical |
| CVE-2021-3129 | Laravel with Ignition <= v8.4.2 Debug Mode - Remote Code Execution | ignition | 9.8 (v3.1) | Critical |
| CVE-2023-25135 | vBulletin <= 5.6.9 - Pre-authentication Remote Code Execution | vbulletin | 9.8 (v3.1) | Critical |
| CVE-2023-39143 | PaperCut < 22.1.3 - Path Traversal | papercut mf | 9.8 (v3.1) | Critical |
| CVE-2023-41892 | CraftCMS < 4.4.15 - Unauthenticated Remote Code Execution | craft cms | 9.8 (v3.1) | Critical |
| CVE-2023-44353 | Adobe ColdFusion WDDX Deserialization Gadgets | coldfusion | 9.8 (v3.1) | Critical |
| CVE-2024-31848 | CData API Server < 23.4.8844 - Path Traversal | API Server | 9.8 (v3.1) | Critical |
| CVE-2024-31849 | CData Connect < 23.4.8846 - Path Traversal | Connect | 9.8 (v3.1) | Critical |
| CVE-2024-50623 | Cleo Harmony < 5.8.0.21 - Arbitary File Read | harmony | 9.8 (v3.1) | Critical |
| CVE-2026-19912 | Kaltura HTML5 Video Player, html5 library Arbitrary Code Execution Vulnerability | Kaltura HTML5 Video Player, html5 library | 9.8 (v3.1) | Critical |
| CVE-2024-8752 | WebIQ 2.15.9 - Directory Traversal | webiq | 9.3 (v4.0) | Critical |
| CVE-2026-65008 | Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData | grav | 9.3 (v4.0) | Critical |
| CVE-2026-10042 | manga-image-translator RCE via Unsafe Pickle Deserialization in Share Model | manga-image-translator | 9.2 (v4.0) | Critical |
| CVE-2026-87930 | MaxSite CMS through 109.6 PHP Object Injection via ci_session | MaxSite CMS | 9.2 (v4.0) | Critical |
| CVE-2026-14602 | Remote API <= 0.2 - Unauthenticated PHP Object Injection via remote-api Query Parameter | Remote API | 9.0 (v3.1) | Critical |
| CVE-2017-9822 | DotNetNuke 5.0.0 - 9.3.0 - Cookie Deserialization Remote Code Execution | dotnetnuke | 8.8 (v3.1) | High |
| CVE-2026-79662 | Ech0 before 4.7.3 OAuth Redirect URI Validation Bypass | Ech0 | 8.8 (v4.0) | High |
| CVE-2021-47795 | GeoVision GeoWebServer <= 5.3.3 - Local File Inclusion / Cross-Site Scripting | geowebserver | 8.7 (v4.0) | High |
| CVE-2024-26291 | Avid NEXIS Agent - Arbitrary File Read | nexis | 8.7 (v4.0) | High |
| CVE-2024-6911 | PerkinElmer ProcessPlus <= 1.11.6507.0 - Local File Inclusion | processplus | 8.7 (v4.0) | High |
| CVE-2025-61666 | Traccar(Windows) 6.1- 6.8.1 - Local File Inclusion | traccar | 8.7 (v4.0) | High |
| CVE-2025-71260 | BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 VIEWSTATE Deserialization RCE | footprints | 8.7 (v4.0) | High |
| CVE-2026-47722 | nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml | nebula-mesh | 8.7 (v4.0) | High |
| CVE-2026-64850 | Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData() | grav | 8.7 (v4.0) | High |
| CVE-2026-71981 | Cypht < 2.12.2 PHP Object Injection RCE via back_query Parameter | cypht | 8.7 (v4.0) | High |
| CVE-2023-43662 | ShokoServer System - Local File Inclusion (LFI) | shokoserver | 8.6 (v3.1) | High |
| CVE-2024-21136 | Oracle Retail Xstore Suite - Pre-authenticated Path Traversal | retail xstore office | 8.6 (v3.1) | High |
| CVE-2024-31850 | CData Arc < 23.4.8839 - Path Traversal | Arc | 8.6 (v3.1) | High |
| CVE-2024-31851 | CData Sync < 23.4.8843 - Path Traversal | Sync | 8.6 (v3.1) | High |
| CVE-2026-49864 | wetty vulnerable to DOM XSS via file-download filename | wetty | 8.6 (v4.0) | High |
| CVE-2026-75833 | Grav API Plugin Open Redirect via Backslash Bypass | grav | 8.6 (v4.0) | High |
| CVE-2026-34931 | hoppscotch: Improper loopback redirect_uri validation in device-login flow | hoppscotch | 8.5 (v4.0) | High |
| CVE-2026-81029 | OpenMetadata before 2.0.0 JWT Disclosure via Unvalidated SAML and OIDC Redirect URI | OpenMetadata | 8.5 (v4.0) | High |
| CVE-2026-81036 | Stalwart Mail Server through 0.16.19 Authorization Code Disclosure via Unvalidated OAuth redirect_uri | stalwart | 8.5 (v4.0) | High |
| CVE-2017-15715 | Apache httpd <=2.4.29 - Arbitrary File Upload | http server | 8.1 (v3.0) | High |
| CVE-2025-6204 | DELMIA Apriso - Command Injection | delmia apriso | 8.0 (v3.1) | High |
| CVE-2026-86207 | N-able N-central - Authentication Bypass | N-central | 7.7 (v4.0) | High |
| CVE-2026-63094 | SigNoz < 0.134.0 SSO OAuth State Manipulation Session Token Theft | signoz | 7.6 (v4.0) | High |
| CVE-2014-3515 | Kerio Control Unified Threat Management 9.1.0 build 1087/9.1.1 build 1324 - Multiple Vulnerabilities | php | 7.5 (v2.0) | High |
| CVE-2014-8142 | Kerio Control Unified Threat Management 9.1.0 build 1087/9.1.1 build 1324 - Multiple Vulnerabilities | php | 7.5 (v2.0) | High |
| CVE-2015-0231 | Kerio Control Unified Threat Management 9.1.0 build 1087/9.1.1 build 1324 - Multiple Vulnerabilities | php | 7.5 (v2.0) | High |
| CVE-2015-1518 | RedaxScript CMS 2.2.0 - SQL Injection | redaxscript | 7.5 (v2.0) | High |
| CVE-2015-2080 | Inductive Automation Ignition 7.8.1 - Remote Leakage Of Shared Buffers | fedora | 7.5 (v3.0) | High |
| CVE-2017-11512 | ManageEngine ServiceDesk 9.3.9328 - Arbitrary File Retrieval | servicedesk | 7.5 (v3.0) | High |
| CVE-2018-10201 | Ncomputing vSPace Pro 10 and 11 - Directory Traversal | vspace pro | 7.5 (v3.0) | High |
| CVE-2018-15811 | DotNetNuke 9.2 - 9.2.1 - Weak Encryption & Cookie Deserialization | dotnetnuke | 7.5 (v3.1) | High |
| CVE-2018-18325 | DotNetNuke 9.2 - 9.2.2 - Weak Encryption & Cookie Deserialization | dotnetnuke | 7.5 (v3.1) | High |
| CVE-2019-12593 | IceWarp Mail Server <=10.4.4 - Local File Inclusion | mail server | 7.5 (v3.0) | High |
| CVE-2021-34805 | FAUST iServer 9.0.018.018.4 - Local File Inclusion | faust iserver | 7.5 (v3.1) | High |
| CVE-2023-0905 | Employee Task Management System v1.0 - Broken Authentication | employee task management system | 7.5 (v3.1) | High |
| CVE-2023-22047 | Oracle Peoplesoft - Unauthenticated File Read | peoplesoft enterprise | 7.5 (v3.1) | High |
| CVE-2023-31059 | Repetier Server - Directory Traversal | repetier-server | 7.5 (v3.1) | High |
| CVE-2023-34843 | Traggo Server - Local File Inclusion | traggo | 7.5 (v3.1) | High |
| CVE-2023-39026 | FileMage Gateway - Directory Traversal | Windows | 7.5 (v3.1) | High |
| CVE-2024-1561 | Gradio 4.3-4.12 - Local File Read | gradio | 7.5 (v3.0) | High |
| CVE-2024-28995 | SolarWinds Serv-U - Directory Traversal | serv-u | 7.5 (v3.1) | High |
| CVE-2024-46938 | Sitecore Experience Platform <= 10.4 - Arbitrary File Read | experience commerce | 7.5 (v3.1) | High |
| CVE-2025-11371 | Gladinet CentreStack & TrioFox - Local File Inclusion | centrestack | 7.5 (v3.1) | High |
| CVE-2025-12055 | MPDV Mikrolab GmbH HYDRA X, MIP 2 & FEDRA 2 - Path Traversal | MIP 2 | 7.5 (v3.1) | High |
| CVE-2026-12720 | Kirki < 6.0.13 - Unauthenticated PHP Object Injection | Kirki | 7.5 (v3.1) | High |
| CVE-2026-19913 | Kaltura HTML5 Video Player, html5lib library Improper Input Validation Vulnerability | Kaltura HTML5 Video Player, html5lib library | 7.5 (v3.1) | High |
| CVE-2026-61686 | SolidInvoice: PHP unserialize() called on client-controlled data in DataGrid LiveComponent context prop | SolidInvoice | 7.5 (v3.1) | High |
| CVE-2026-53728 | Medplum - Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakage | medplum | 7.1 (v3.1) | High |
| CVE-2026-79786 | Coroot 1.20.2 through 1.24.5 Unvalidated Redirect URI in MCP OAuth Client Registration | coroot | 7.0 (v4.0) | High |
| CVE-2025-71257 | BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication Bypass | footprints itsm | 6.9 (v4.0) | Medium |
| CVE-2026-86206 | N-able N-central - Access Control Bypass via Path Confusion and Forwarded Header Spoofing | N-central | 6.9 (v4.0) | Medium |
| CVE-2018-6671 | McAfee ePO 5.9.1 - Registered Executable Local Access Bypass | epolicy orchestrator | 6.5 (v3.0) | Medium |
| CVE-2021-21402 | Jellyfin <10.7.0 - Local File Inclusion | jellyfin | 6.5 (v3.1) | Medium |
| CVE-2012-4940 | Axigen Mail Server Filename Directory Traversal | axigen free mail server | 6.4 (v2.0) | Medium |
| CVE-2017-1000163 | Phoenix Framework - Open Redirect | phoenix | 6.1 (v3.0) | Medium |
| CVE-2019-10092 | Apache HTTP Server <=2.4.39 - HTML Injection/Partial Cross-Site Scripting | http server | 6.1 (v3.1) | Medium |
| CVE-2026-33213 | Redash: Open redirect vulnerability in post-login redirect handling | redash | 6.1 (v3.1) | Medium |
| CVE-2026-34442 | FreeScout: Host Header Injection Leading to External Resource Loading and Open Redirect in FreeScout | freescout | 6.1 (v3.1) | Medium |
| CVE-2026-34847 | hoppscotch: Open redirect via /enter?redirect= | hoppscotch | 6.1 (v3.1) | Medium |
| CVE-2026-35404 | Open edX Platform has an Open Redirect in Survey Views via Unvalidated redirect_url Parameter | openedx | 6.1 (v3.1) | Medium |
| CVE-2026-40295 | Devise: Open Redirect via Unvalidated request.referrer in Timeoutable Session Timeout Handler | devise | 6.1 (v3.1) | Medium |
| CVE-2017-9965 | Schneider Electric Pelco VideoXpert Enterprise 2.0 - Path Traversal | pelco videoxpert | 5.8 (v3.0) | Medium |
| CVE-2026-75628 | Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login because same_origin_pa | - | 5.7 (v3.1) | Medium |
| CVE-2017-3528 | Oracle E-Business Suite 12.1.3/12.2.x - Open Redirect | applications framework | 5.4 (v3.0) | Medium |
| CVE-2026-18266 | Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability | Dify | 5.4 (v3.0) | Medium |
| CVE-2018-16133 | Cybrotech CyBroHttpServer 1.0.3 - Directory Traversal | cybrohttpserver | 5.3 (v3.0) | Medium |
| CVE-2019-18393 | Ignite Realtime Openfire <4.42 - Local File Inclusion | openfire | 5.3 (v3.1) | Medium |
| CVE-2025-11368 | LearnPress < 4.3.0 - Arbitrary Callback Execution to Information Exposure | learnpress | 5.3 (v3.1) | Medium |
| CVE-2026-16336 | trinodb trino OAuth2/OIDC ExternalUriInfo.java redirect | trino | 5.3 (v4.0) | Medium |
| CVE-2026-34959 | Adminer before 5.5.0 Open Redirect via X-Forwarded-Prefix | adminer | 5.3 (v4.0) | Medium |
| CVE-2026-63768 | cal.diy 6.2.0 Conferencing OAuth Callback Open Redirect via Unsigned State | cal.diy | 5.3 (v4.0) | Medium |
| CVE-2026-80200 | Kimai before 2.53.0 Open Redirect via RelayState | kimai | 5.3 (v4.0) | Medium |
| CVE-2026-82274 | Twenty Open Redirect via OAuth Propagator Callback | twenty | 5.3 (v4.0) | Medium |
| CVE-2026-8385 | WordPress WP Go Maps < 10.0.10 - Unauthenticated Marker Data Disclosure | wp-google-maps | 5.3 (v3.1) | Medium |
| CVE-2026-85676 | Dub Open Redirect via Unrestricted redir_url Parameter | dub | 5.3 (v4.0) | Medium |
| CVE-2026-86205 | h3 before 2.0.1-rc.18 Open Redirect via redirectBack() | h3 | 5.3 (v4.0) | Medium |
| CVE-2026-86756 | Snipe-IT 8.5.0 through 8.6.3 Open Redirect via SAML RelayState | snipe-it | 5.3 (v4.0) | Medium |
| CVE-2026-32113 | Discourse: Open redirect via sso_destination_url cookie in enter | discourse | 5.1 (v4.0) | Medium |
| CVE-2026-35396 | WeGIA - Open Redirect - IsaidaControle - listarId() - Unvalidated $_GET['nextPage'] | wegia | 5.1 (v4.0) | Medium |
| CVE-2026-35398 | WeGIA - Open Redirect - OrigemControle - listarTodos() & listarId_Nome() - Unvalidated $_GET['nextPage'] | wegia | 5.1 (v4.0) | Medium |
| CVE-2026-35472 | WeGIA - Open Redirect - EstoqueControle - listarTodos() - Unvalidated $_GET['nextPage'] | wegia | 5.1 (v4.0) | Medium |
| CVE-2026-35473 | WeGIA - Open Redirect - IentradaControle - listarId() - Unvalidated $_GET['nextPage'] | wegia | 5.1 (v4.0) | Medium |
| CVE-2026-35474 | WeGIA - Open Redirect - atualizacao redirection - Unvalidated $_GET['redirect'] | wegia | 5.1 (v4.0) | Medium |
| CVE-2026-35475 | WeGIA - Open Redirect - backup redirection — Unvalidated $_GET['redirect'] | wegia | 5.1 (v4.0) | Medium |
| CVE-2026-42350 | Kargo: Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter | kargo | 5.1 (v4.0) | Medium |
| CVE-2026-55185 | Miniflux 2: Open Redirect Bypass | v2 | 5.1 (v4.0) | Medium |
| CVE-2026-66414 | Leantime Open Redirect in Login Controller via redirectUrl Parameter | Leantime | 5.1 (v4.0) | Medium |
| CVE-2026-73671 | Saurus CMS Unauthenticated Open Redirect via logout url parameter | Saurus CMS Community Edition | 5.1 (v4.0) | Medium |
| CVE-2026-86256 | wger before 2.6 Open Redirect via trainer-login next parameter | wger | 5.1 (v4.0) | Medium |
| CVE-2026-89148 | AVideo Open Redirect via playlistSort.php Referer Header | AVideo | 5.1 (v4.0) | Medium |
| CVE-2019-2588 | Oracle Business Intelligence - Path Traversal | business intelligence publisher | 4.9 (v3.0) | Medium |
| CVE-2026-51564 | the redirect parameter in Milk admin <=0.9.8 Open Redirect Vulnerability | - | 4.9 (v3.1) | Medium |
| CVE-2018-20418 | Craft CMS 3.0.25 - Cross-Site Scripting | craft cms | 4.8 (v3.0) | Medium |
| CVE-2026-43924 | FOSSBilling has an open redirect via administrator-configured redirect targets | FOSSBilling | 4.8 (v4.0) | Medium |
| CVE-2026-14236 | Contact Form 7 – PayPal & Stripe Add-on < 2.5 - Open Redirect | Contact Form 7 | 4.7 (v3.1) | Medium |
| CVE-2026-42329 | Iris has an Open Redirect issue | iris-web | 4.7 (v3.1) | Medium |
| CVE-2015-2275 | WoltLab Community Gallery - Persistent Cross-Site Scripting | community gallery | 4.3 (v2.0) | Medium |
| CVE-2026-35411 | Directus is an Open Redirect in Admin 2FA Setup Page | directus | 4.3 (v3.1) | Medium |
| CVE-2026-48012 | Shopware SSO referer trust leading to an arbitrary redirect target | shopware | 4.3 (v3.1) | Medium |
| CVE-2026-53683 | Freeipa: idm: idm/freeipa web ui - client-side open redirect in reset_password.html | Red Hat Enterprise Linux 10 | 4.3 (v3.1) | Medium |
| CVE-2026-55834 | Pocket ID: Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none | pocket-id | 4.3 (v3.1) | Medium |
| CVE-2026-16297 | Clearfy < 2.4.3 - Admin+ PHP Object Injection via Settings Import | Clearfy Cache | 4.1 (v3.1) | Medium |
| CVE-2024-4841 | LoLLMS WebUI - Subfolder Prediction via Path Traversal | lollms-webui | 3.3 (v3.1) | Low |
| CVE-2026-11477 | hs-web hsweb-framework OAuth2 Client OAuth2Client.java OAuth2Client redirect | hsweb-framework | 2.1 (v4.0) | Low |
| CVE-2026-67350 | Serendipity < 2.6.1 Open Redirect via exit.php | Serendipity | 2.1 (v4.0) | Low |
| CVE-2026-11502 | JeecgBoot Third-Party Login ThirdLoginController.java HttpServletResponse.sendRedirect redirect | JeecgBoot | 1.3 (v4.0) | Low |
Observed CWEs
These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.