On this page
Atomicorp WAF Rule 351000
Rule Summary
- Rule ID: 351000
- Status: Active
- Alert message: Atomicorp.com Upload Malware Scanner: Malicious File upload attempt detected and blocked
- Observed CWEs: CWE-20 (1), CWE-22 (1), CWE-73 (1), CWE-79 (1), CWE-284 (23), CWE-306 (5), CWE-352 (1), CWE-434 (54)
- Revision: 2
- Rule severity: Critical (2)
- Phase: 2 (request body)
- Rule action: deny
- HTTP status: 403
- Logging: log, auditlog
Description
This rule detects behavior identified by its current alert as “Atomicorp.com Upload Malware Scanner: Malicious File upload attempt detected and blocked”. It evaluates during the request body phase and denies matching traffic with HTTP status 403.
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
| CVE | Vulnerability | Product | CVSS | Severity |
|---|---|---|---|---|
| CVE-2025-34163 | Dongsheng Logistics Software Unauthenticated Arbitrary File Upload | Dongsheng Logistics Software | 10.0 (v4.0) | Critical |
| CVE-2026-57827 | Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 | rsfiles! | 10.0 (v4.0) | Critical |
| CVE-2015-10138 | Work The Flow File Upload <= 2.5.2 - Arbitrary File Upload | work the flow file upload | 9.8 (v3.1) | Critical |
| CVE-2025-9314 | Developer Tools <= 1.1.3 – Unauthenticated Arbitrary File Upload | The Developer Tools WordPress plugin through 1.1.3 | 9.8 (v3.1) | Critical |
| CVE-2026-36669 | ck_upload_handler.php in Feng Office 3.11.13.11 Arbitrary File Upload Vulnerability | ck upload handler.php in Feng Office 3.11.13.11 | 9.8 (v3.1) | Critical |
| CVE-2026-49827 | WebErpMesv2 has Unauthenticated RCE via Unrestricted File Upload in HR Expense scan_file (CWE-434) | WebErpMesv2 | 9.8 (v3.1) | Critical |
| CVE-2026-50894 | easyadmin v2.0.2.2 Arbitrary Code Execution Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2026-67678 | RainyGao-Hithub DocSys v.2.02.80 Arbitrary Code Execution Vulnerability | RainyGao-Hithub DocSys v.2.02.80 | 9.8 (v3.1) | Critical |
| CVE-2026-75327 | In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java Arbitrary File Upload Vulnerability | In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java | 9.8 (v3.1) | Critical |
| CVE-2016-20052 | Snews CMS 1.7 Unrestricted File Upload via snews_files | snews | 9.3 (v4.0) | Critical |
| CVE-2018-25412 | Delta Sql 1.8.2 Arbitrary File Upload via docs_upload.php | deltasql | 9.3 (v4.0) | Critical |
| CVE-2021-47940 | WordPress Download From Files 1.48 Arbitrary File Upload | Download From Files | 9.3 (v4.0) | Critical |
| CVE-2022-4995 | Weaver E-cology 9.0 File Upload RCE via uploaderOperate.jsp | E-cology 9.0 | 9.3 (v4.0) | Critical |
| CVE-2026-70558 | Dinky Unauthenticated Arbitrary File Write via /download/uploadFromRsByLocal Gated Only by Hardcoded Default Token | Dinky | 9.3 (v4.0) | Critical |
| CVE-2026-49849 | xShop: Unrestricted File Upload in File Attachment Module in Admin panel leads to Arbitrary Code Execution | xshop | 9.1 (v3.1) | Critical |
| CVE-2025-70151 | scholars tracking system Arbitrary Code Execution Vulnerability | scholars tracking system | 8.8 (v3.1) | High |
| CVE-2026-55676 | Malcolm vulnerable to RCE via unrestricted .php upload to the file-upload component | Malcolm | 8.8 (v3.1) | High |
| CVE-2026-60009 | theia Arbitrary Code Execution Vulnerability | theia | 8.8 (v3.1) | High |
| CVE-2026-72557 | Cockpit CMS Cockpit CMS - Unrestricted File Upload | Cockpit CMS | 8.8 (v3.1) | High |
| CVE-2018-25409 | SIM-PKH 2.4.1 Arbitrary File Upload via aksi_pengurus.php | SIM-PKH | 8.7 (v4.0) | High |
| CVE-2019-25673 | UniSharp Laravel File Manager v2.0.0-alpha7 Arbitrary File Upload | Laravel File Manager | 8.7 (v4.0) | High |
| CVE-2026-26212 | Rara One Click Demo Import < 1.3.5 Arbitrary File Upload RCE | Rara One Click Demo Import | 8.6 (v4.0) | High |
| CVE-2026-63429 | HeyForm has unauthenticated /api/upload endpoint that accepts arbitrary files with no auth/session/form context | heyform | 8.6 (v3.1) | High |
| CVE-2026-82524 | UnoPim File Upload RCE via TinyMCE Image Upload Endpoint | unopim | 8.6 (v4.0) | High |
| CVE-2026-13157 | Theme Demo Import <= 1.1.3 - Admin+ Arbitrary File Upload | Theme Demo Import | 7.2 (v3.1) | High |
| CVE-2026-13158 | Everest Toolkit <= 1.2.3 - Admin+ Arbitrary File Upload | Everest Toolkit | 7.2 (v3.1) | High |
| CVE-2026-7537 | MDJM Event Management <= 1.7.8.3 - Authenticated (Administrator+) Arbitrary File Upload via 'mdjm_email_upload_file' Par | MDJM Event Management | 7.2 (v3.1) | High |
| CVE-2026-56702 | Adminer before 5.4.3 Unrestricted File Upload via AdminerFileUpload | adminer | 7.1 (v4.0) | High |
| CVE-2026-16548 | Bit Assist < 1.8.2 - Unauthenticated Arbitrary File Upload via Response Endpoint | Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat | 6.5 (v3.1) | Medium |
| CVE-2026-42538 | IRIS has an Insecure File Upload | iris-web | 6.3 (v3.1) | Medium |
| CVE-2026-11474 | Kushan2k student-management-system Registration Endpoint RegisterService.php unrestricted upload | student-management-system | 5.5 (v4.0) | Medium |
| CVE-2026-18788 | Trippo ResponsiveFilemanager dialog.php unrestricted upload | ResponsiveFilemanager | 5.5 (v4.0) | Medium |
| CVE-2026-5573 | Technostrobe HI-LED-WR120-G2 fs unrestricted upload | hi-led-wr120-g2 firmware | 5.5 (v4.0) | Medium |
| CVE-2026-78202 | itsourcecode Payroll System admin_class.php save_settings unrestricted upload | Payroll System | 5.5 (v4.0) | Medium |
| CVE-2026-78245 | itsourcecode Online Pharmacy System User Registration register.php move_uploaded_file unrestricted upload | Online Pharmacy System | 5.5 (v4.0) | Medium |
| CVE-2026-85208 | itsourcecode Online Medicine Delivery System Order Management Controller controller.php doInsert unrestricted upload | Online Medicine Delivery System | 5.5 (v4.0) | Medium |
| CVE-2026-86239 | liufee FeehiCMS UEditor Widget UeditorAction.php init unrestricted upload | FeehiCMS | 5.5 (v4.0) | Medium |
| CVE-2026-86305 | light0011 cms Upload.class.php upload unrestricted upload | cms | 5.5 (v4.0) | Medium |
| CVE-2026-86666 | aircheng-org iWebShop-5 pic.php uploadFile unrestricted upload | iWebShop-5 | 5.5 (v4.0) | Medium |
| CVE-2026-36722 | the /api/create-car-image component of bookcars v8.3 Arbitrary Code Execution Vulnerability | the /api/create-car-image component of bookcars v8.3 | 5.4 (v3.1) | Medium |
| CVE-2026-55419 | Reachy Mini: Unrestricted Upload of File with Dangerous Type | reachy mini | 5.3 (v3.1) | Medium |
| CVE-2026-74908 | Grav plugin-api before 1.0.15 Script Injection via SVG | grav | 5.1 (v4.0) | Medium |
| CVE-2026-78337 | Unrestricted upload of file with dangerous type in Prospero Flow CRM allows stored cross-site scripting via SVG | Prospero Flow CRM | 4.8 (v4.0) | Medium |
| CVE-2026-81931 | Unrestricted upload of file with dangerous type in Prospero Flow CRM product photo allows stored cross-site scripting | Prospero Flow CRM | 4.8 (v4.0) | Medium |
| CVE-2024-14046 | OpenBoxes Document Upload Controller DocumentController.groovy DocumentController unrestricted upload | OpenBoxes | 2.1 (v4.0) | Low |
| CVE-2025-13815 | moxi159753 Mogu Blog v2 pictures unrestricted upload | mogublog | 2.1 (v4.0) | Low |
| CVE-2026-10806 | mjperpinosa stumasy add_post.php unrestricted upload | stumasy | 2.1 (v4.0) | Low |
| CVE-2026-10807 | mjperpinosa stumasy change_profile_image.php unrestricted upload | stumasy | 2.1 (v4.0) | Low |
| CVE-2026-16451 | zsadmin2025 ZS-Admin com.zs.file.controller.SysFileController upload unrestricted upload | ZS-Admin | 2.1 (v4.0) | Low |
| CVE-2026-19210 | SourceCodester Photo Share Website ajax.php save_upload unrestricted upload | Photo Share Website | 2.1 (v4.0) | Low |
| CVE-2026-77681 | CodeAstro Online Job Portal update-profile.php unrestricted upload | Online Job Portal | 2.1 (v4.0) | Low |
| CVE-2026-82679 | diem-project diem Widget Editor dmWidgetContentBaseMediaForm.php unrestricted upload | diem | 2.1 (v4.0) | Low |
| CVE-2026-85186 | itsourcecode Online Medicine Delivery System Customer Controller controller.php doupdateimage unrestricted upload | Online Medicine Delivery System | 2.1 (v4.0) | Low |
| CVE-2026-19383 | saithink/saigroup SaiAdmin Plugin Upload Endpoint upload shell_exec unrestricted upload | SaiAdmin | 2.0 (v4.0) | Low |
| CVE-2026-19839 | SourceCodester Simple Doctors Appointment System save_file.php save_doctor unrestricted upload | Simple Doctors Appointment System | 2.0 (v4.0) | Low |
| CVE-2026-5576 | SourceCodester/jkev Record Management System Add Employee save_emp.php unrestricted upload | Record Management System | 2.0 (v4.0) | Low |
| CVE-2026-76995 | SourceCodester Simple Online Food Ordering System ajax.php save_menu unrestricted upload | Simple Online Food Ordering System | 2.0 (v4.0) | Low |
| CVE-2026-82629 | jeecgboot jeewx-boot doUpload Endpoint MyJwWebJwid3Controller.java MyJwWebJwid3Controller.doUpload unrestricted upload | jeewx-boot | 2.0 (v4.0) | Low |
Observed CWEs
These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.
Documentation Source
- Original wiki page: WAF 351000
- Source revision: 2695
- Source revision date: 2012-09-18