On this page

Atomicorp WAF Rule 390501

Rule Summary

  • Rule ID: 390501
  • Status: Active
  • Alert message: Atomicorp.com Malware Script Blacklist: Known Malware detected in Request Filename
  • Observed CWEs: CWE-79 (1), CWE-94 (1), CWE-284 (1), CWE-434 (4), CWE-601 (1)
  • Revision: 4
  • Rule severity: Critical (2)
  • Phase: 2 (request body)
  • Request surfaces: Request filename
  • Rule action: deny
  • HTTP status: 404
  • Logging: log, auditlog

Description

This rule detects when a known malware filename has been detected in a request from a client to the server. Either the client is trying to load or find the malware on the system, for example a web shell, is is trying to install or upload the malware.

Troubleshooting

False Positives

There are no known false positives with this rule. If you believe this is a false positive, please report this to our security team to determine if this is a legitimate case, or if its clever attack on your system. Do not disable this rule.

Instructions to report false positives are detailed on the Reporting False Positives wiki page. If it is a false positive, we will fix the issue in the rules and get a release out to you promptly.

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

CVEVulnerabilityProductCVSSSeverity
CVE-2026-67206Wolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Uploadwolfcms8.7 (v4.0)High
CVE-2026-56703Adminer before 5.4.3 Remote Code Execution via SQLite VACUUM INTOadminer8.6 (v4.0)High
CVE-2026-53599Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mocore7.5 (v3.1)High
CVE-2026-13158Everest Toolkit <= 1.2.3 - Admin+ Arbitrary File UploadEverest Toolkit7.2 (v3.1)High
CVE-2020-18268Z-Blog <=1.5.2 - Open Redirectz-blogphp6.1 (v3.1)Medium
CVE-2026-27176MajorDoMo - Cross-Site Scriptingmajordomo5.1 (v4.0)Medium
CVE-2026-5576SourceCodester/jkev Record Management System Add Employee save_emp.php unrestricted uploadRecord Management System2.0 (v4.0)Low
CVE-2025-32101UNA CMS <= 14.0.0-RC4 - PHP Object Injection-N/AN/A

Observed CWEs

These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.

CWERelated Published CVEs
CWE-79CVE-2026-27176
CWE-94CVE-2026-56703
CWE-284CVE-2026-5576
CWE-434CVE-2026-67206 , CVE-2026-53599 , CVE-2026-13158 , CVE-2026-5576
CWE-601CVE-2020-18268

Documentation Source

  • Original wiki page: WAF 390501
  • Source revision: 6050
  • Source revision date: 2020-08-24