On this page

Atomicorp WAF Rule 360151

Rule Summary

  • Rule ID: 360151
  • Status: Active
  • Alert message: Atomicorp.com WAF Rules: Injection Attack: Variable Function Call Found
  • Observed CWEs: CWE-20 (2), CWE-79 (3), CWE-89 (1), CWE-94 (6), CWE-95 (1), CWE-287 (1), CWE-798 (1), CWE-913 (2), CWE-918 (1), CWE-1188 (1)
  • Revision: 43
  • Rule severity: Critical (2)
  • Phase: 2 (request body)
  • Request surfaces: Request cookies, Request argument names, Request arguments, JSON request data, SOAP request data, XML request data
  • Rule action: deny
  • HTTP status: 403
  • Logging: log, auditlog

Description

This rule detects Possible PHP injection attacks. It does this by looking for combinations of metacharacters and word/character segements encapsulated by parenthesese that may appear to be PHP variable function calls. If you have a false positive with this rule, please report it to us.

Troubleshooting

False Positives

If you believe this is a false positive, please report this to our security team to determine if this is a legitimate case, or if its clever attack on your system. Instructions to report false positives are detailed on the Reporting False Positives wiki page. If it is a false positive, we will fix the issue in the rules and get a release out to you promptly.

Tuning Guidance

If you want to disable or tune this rule, please see the Tuning the Atomicorp WAF Rules page for basic information.

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

CVEVulnerabilityProductCVSSSeverity
CVE-2026-47668DbGate - Remote Code Execution via Anonymous JWTdbgate10.0 (v3.1)Critical
CVE-2026-53753Crawl4AI <= 0.8.6 - Remote Code Executioncrawl4ai10.0 (v3.1)Critical
CVE-2019-10758mongo-express Remote Code Executionmongo-express9.9 (v3.1)Critical
CVE-2026-34156NocoBase - VM Sandbox Escape to Remote Code Executionnocobase9.9 (v3.1)Critical
CVE-2019-1935Cisco UCS Director_ Cisco Integrated Management Controller Supervisor and Cisco UCS Director Express for Big Data - Multiple Vulnerabilitiesintegrated management controller supervisor9.8 (v3.1)Critical
CVE-2019-1937Cisco UCS Director_ Cisco Integrated Management Controller Supervisor and Cisco UCS Director Express for Big Data - Multiple Vulnerabilitiesintegrated management controller supervisor9.8 (v3.0)Critical
CVE-2026-61511vBulletin 6.x - Remote Code ExecutionvBulletin9.3 (v4.0)Critical
CVE-2025-1302JSONPath Plus < 10.3.0 - Remote Code Executionjsonpath-plus8.9 (v4.0)High
CVE-2023-7137Client Details System 1.0 - SQL Injectionclient details system8.8 (v3.1)High
CVE-2026-0560LolLMS < 2.2.0 - Server-Side Request Forgerylollms7.5 (v3.1)High
CVE-2024-46507Yeti Platform < 2.1.12 - Server-Side Template Injection to RCEyeti7.3 (v3.1)High
CVE-2019-1936Cisco UCS Director_ Cisco Integrated Management Controller Supervisor and Cisco UCS Director Express for Big Data - Multiple Vulnerabilitiesintegrated management controller supervisor7.2 (v3.1)High
CVE-2023-24488Citrix Gateway and Citrix ADC - Cross-Site Scriptinggateway6.1 (v3.1)Medium
CVE-2024-24494Daily Habit Tracker 1.0 - Stored Cross-Site Scripting (XSS)daily habit tracker6.1 (v3.1)Medium
CVE-2020-24963Best Support System 3.0.4 - 'ticket_body' Persistent XSS (Authenticated)best support system5.4 (v3.1)Medium
CVE-2024-28397pyload-ng js2py - Remote Code Executionpyload5.3 (v3.1)Medium

Observed CWEs

These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.

CWERelated Published CVEs
CWE-20CVE-2026-47668 , CVE-2019-1936
CWE-79CVE-2023-24488 , CVE-2024-24494 , CVE-2020-24963
CWE-89CVE-2023-7137
CWE-94CVE-2026-47668 , CVE-2026-53753 , CVE-2019-10758 , CVE-2025-1302 , CVE-2024-46507 , CVE-2024-28397
CWE-95CVE-2026-61511
CWE-287CVE-2019-1937
CWE-798CVE-2019-1935
CWE-913CVE-2026-53753 , CVE-2026-34156
CWE-918CVE-2026-0560
CWE-1188CVE-2026-47668

Documentation Source

  • Original wiki page: WAF 360151
  • Source revision: 6397
  • Source revision date: 2023-10-05