On this page
Atomicorp WAF Rule 390704
Rule Summary
- Rule ID: 390704
- Status: Active
- Alert message: Atomicorp.com WAF Rules: Possible Encoding Abuse Attack Attempt
- Observed CWEs: CWE-20 (1), CWE-22 (1), CWE-74 (2), CWE-78 (2), CWE-79 (4), CWE-89 (9), CWE-200 (4), CWE-295 (2), CWE-306 (1), CWE-352 (3), CWE-611 (1), CWE-640 (1), CWE-798 (1)
- Revision: 1
- Rule severity: Notice (5)
- Phase: 2 (request body)
- Request surfaces: Request headers
- Rule action: deny
- HTTP status: 400
- Logging: log, auditlog
Description
This rule detects behavior identified by its current alert as “Possible Encoding Abuse Attack Attempt” in the request headers. It evaluates during the request body phase and denies matching traffic with HTTP status 400.
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
| CVE | Vulnerability | Product | CVSS | Severity |
|---|---|---|---|---|
| CVE-2010-2861 | Adobe ColdFusion - Directory Traversal | coldfusion | 9.8 (v3.1) | Critical |
| CVE-2012-5686 | ZPanel 10.0.1 - Cross-Site Request Forgery / Cross-Site Scripting / SQL Injection / Password Reset | zpanel | 9.8 (v3.1) | Critical |
| CVE-2016-2386 | SAP NetWeaver J2EE Engine 7.40 - SQL Injection | netweaver application server java | 9.8 (v3.1) | Critical |
| CVE-2017-9811 | Kaspersky Anti-Virus File Server 8.0.3.297 - Multiple Vulnerabilities | anti-virus for linux server | 9.8 (v3.0) | Critical |
| CVE-2018-6220 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | 9.8 (v3.0) | Critical |
| CVE-2018-6223 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | 9.8 (v3.0) | Critical |
| CVE-2018-6228 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | 9.8 (v3.0) | Critical |
| CVE-2018-6229 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | 9.8 (v3.0) | Critical |
| CVE-2022-31181 | PrestaShop - SQL Injection to Eval Injection | prestashop | 9.8 (v3.1) | Critical |
| CVE-2017-9810 | Kaspersky Anti-Virus File Server 8.0.3.297 - Multiple Vulnerabilities | anti-virus for linux server | 8.8 (v3.0) | High |
| CVE-2018-6224 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | 8.8 (v3.0) | High |
| CVE-2018-6221 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | 8.1 (v3.0) | High |
| CVE-2018-6222 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | 7.8 (v3.0) | High |
| CVE-2016-3473 | Oracle BI Publisher 11.1.1.6.0/11.1.1.7.0/11.1.1.9.0/12.2.1.0.0 - XML External Entity Injection | business intelligence publisher | 7.7 (v3.0) | High |
| CVE-2012-5685 | ZPanel 10.0.1 - Cross-Site Request Forgery / Cross-Site Scripting / SQL Injection / Password Reset | zpanel | 7.5 (v2.0) | High |
| CVE-2013-5694 | Opsview pre 4.4.1 - Blind SQL Injection | opsview | 7.5 (v2.0) | High |
| CVE-2015-1428 | Sefrengo CMS 1.6.1 - Multiple SQL Injections | sefrengo | 7.5 (v2.0) | High |
| CVE-2017-9812 | Kaspersky Anti-Virus File Server 8.0.3.297 - Multiple Vulnerabilities | anti-virus for linux server | 7.5 (v3.0) | High |
| CVE-2018-7448 | CMS Made Simple 2.1.6 - Remote Code Execution | cms made simple | 7.5 (v3.0) | High |
| CVE-2024-0566 | Smart Manager 8.27.0 - Post-Authenticated SQL Injection | smart manager | 7.2 (v3.1) | High |
| CVE-2012-5683 | ZPanel 10.0.1 - Cross-Site Request Forgery / Cross-Site Scripting / SQL Injection / Password Reset | zpanel | 6.8 (v2.0) | Medium |
| CVE-2018-6230 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | 6.8 (v3.0) | Medium |
| CVE-2018-6219 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | 6.5 (v3.0) | Medium |
| CVE-2017-9813 | Kaspersky Anti-Virus File Server 8.0.3.297 - Multiple Vulnerabilities | anti-virus for linux server | 6.1 (v3.0) | Medium |
| CVE-2018-6226 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | 5.4 (v3.0) | Medium |
| CVE-2018-6227 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | 5.4 (v3.0) | Medium |
| CVE-2016-1910 | SAP NetWeaver J2EE Engine 7.40 - SQL Injection | netweaver | 5.3 (v3.0) | Medium |
| CVE-2016-2388 | SAP NetWeaver J2EE Engine 7.40 - SQL Injection | netweaver application server java | 5.3 (v3.1) | Medium |
| CVE-2012-5684 | ZPanel 10.0.1 - Cross-Site Request Forgery / Cross-Site Scripting / SQL Injection / Password Reset | zpanel | 4.3 (v2.0) | Medium |
| CVE-2018-6225 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | 4.3 (v3.0) | Medium |
Observed CWEs
These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.