On this page
Atomicorp WAF Rule 390716
Rule Summary
- Rule ID: 390716
- Status: Active
- Alert message: Atomicorp.com WAF Rules: URL file extension is restricted by policy
- Observed CWEs: CWE-22 (23), CWE-23 (1), CWE-32 (1), CWE-35 (1), CWE-36 (1), CWE-79 (2), CWE-89 (1), CWE-91 (1), CWE-113 (1), CWE-200 (10), CWE-259 (1), CWE-284 (1), CWE-287 (1), CWE-306 (3), CWE-425 (1), CWE-522 (4), CWE-532 (4), CWE-552 (4), CWE-601 (1), CWE-798 (2), CWE-1258 (1)
- Revision: 2
- Rule severity: Error (3)
- Phase: 2 (request body)
- Rule action: deny
- HTTP status: 403
- Logging: log, auditlog
Description
This rule detects behavior identified by its current alert as “URL file extension is restricted by policy”. It evaluates during the request body phase and denies matching traffic with HTTP status 403.
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
| CVE | Vulnerability | Product | CVSS | Severity |
|---|---|---|---|---|
| CVE-2017-11165 | DataTaker DT80 dEX 1.50.012 - Information Disclosure | dt80 dex firmware | 9.8 (v3.1) | Critical |
| CVE-2017-14942 | Intelbras WRN 150 - Authentication Bypass | wrn150 | 9.8 (v3.0) | Critical |
| CVE-2017-8225 | GoAhead Camera - Credential Disclosure | wireless ip camera (p2p) firmware | 9.8 (v3.0) | Critical |
| CVE-2018-0127 | Cisco RV132W/RV134W Router - Information Disclosure | rv132w firmware | 9.8 (v3.1) | Critical |
| CVE-2018-7251 | Anchor CMS 0.12.3 - Error Log Exposure | anchor | 9.8 (v3.0) | Critical |
| CVE-2019-19781 | Citrix ADC and Gateway - Directory Traversal | application delivery controller firmware | 9.8 (v3.1) | Critical |
| CVE-2022-34045 | WAVLINK WN530HG4 - Improper Access Control | wl-wn530hg4 firmware | 9.8 (v3.1) | Critical |
| CVE-2023-34362 | MOVEit Transfer - Remote Code Execution | moveit cloud | 9.8 (v3.1) | Critical |
| CVE-2024-32238 | H3C ER8300G2-X - Password Disclosure | - | 9.8 (v3.1) | Critical |
| CVE-2024-44000 | LiteSpeed Cache <= 6.4.1 - Sensitive Information Exposure | litespeed cache | 9.8 (v3.1) | Critical |
| CVE-2024-7332 | TOTOLINK CP450 v4.1.0cu.747_B20191224 - Hard-Coded Password Vulnerability | cp450 firmware | 9.3 (v4.0) | Critical |
| CVE-2024-8752 | WebIQ 2.15.9 - Directory Traversal | webiq | 9.3 (v4.0) | Critical |
| CVE-2024-52875 | Kerio Control v9.2.5 - CRLF Injection | kerio control | 8.8 (v3.1) | High |
| CVE-2021-47795 | GeoVision GeoWebServer <= 5.3.3 - Local File Inclusion / Cross-Site Scripting | geowebserver | 8.7 (v4.0) | High |
| CVE-2023-7327 | Ozeki 10 SMS Gateway 10.3.208 - Arbitrary File Read | Ozeki SMS Gateway | 8.7 (v4.0) | High |
| CVE-2023-43662 | ShokoServer System - Local File Inclusion (LFI) | shokoserver | 8.6 (v3.1) | High |
| CVE-2018-12455 | Intelbras NPLUG 1.0.0.14 - Authentication Bypass | nplug | 8.1 (v3.0) | High |
| CVE-2017-1000028 | Oracle GlassFish Server Open Source Edition 4.1 - Local File Inclusion | glassfish server | 7.5 (v3.0) | High |
| CVE-2017-16806 | Ulterius Server < 1.9.5.0 - Directory Traversal | ulterius server | 7.5 (v3.0) | High |
| CVE-2018-10201 | Ncomputing vSPace Pro 10 and 11 - Directory Traversal | vspace pro | 7.5 (v3.0) | High |
| CVE-2018-8727 | Mirasys DVMS Workstation <=5.12.6 - Local File Inclusion | dvms workstation | 7.5 (v3.0) | High |
| CVE-2019-14322 | Pallets Werkzeug <0.15.5 - Local File Inclusion | Windows | 7.5 (v3.1) | High |
| CVE-2019-19822 | TOTOLINK/Realtek Routers - Information Disclosure | a3002ru firmware | 7.5 (v3.1) | High |
| CVE-2019-19823 | TOTOLINK/Realtek Routers - Information Disclosure | a3002ru firmware | 7.5 (v3.1) | High |
| CVE-2020-10973 | WAVLINK - Access Control | wn530hg4 firmware | 7.5 (v3.1) | High |
| CVE-2020-14864 | Oracle Fusion - Directory Traversal/Local File Inclusion | business intelligence | 7.5 (v3.1) | High |
| CVE-2021-34805 | FAUST iServer 9.0.018.018.4 - Local File Inclusion | faust iserver | 7.5 (v3.1) | High |
| CVE-2021-40150 | Reolink E1 Zoom Camera <=3.0.0.716 - Information Disclosure | e1 zoom firmware | 7.5 (v3.1) | High |
| CVE-2021-40661 | IND780 - Local File Inclusion | ind780 firmware | 7.5 (v3.1) | High |
| CVE-2022-23854 | AVEVA InTouch Access Anywhere Secure Gateway - Local File Inclusion | intouch access anywhere | 7.5 (v3.1) | High |
| CVE-2022-27043 | Yearning - Directory Traversal | yearning | 7.5 (v3.1) | High |
| CVE-2023-2766 | Weaver OA 9.5 - Information Disclosure | weaver office automation | 7.5 (v3.1) | High |
| CVE-2023-39026 | FileMage Gateway - Directory Traversal | Windows | 7.5 (v3.1) | High |
| CVE-2023-40600 | EWWW Image Optimizer <= 7.2.0 - Unauthenticated Information Disclosure | image optimizer | 7.5 (v3.1) | High |
| CVE-2023-43261 | Milesight Routers - Information Disclosure | ur51 | 7.5 (v3.1) | High |
| CVE-2023-44982 | WordPress Perfect Images (WP Retina 2x) < 6.4.6 - Sensitive Information Exposure | perfect images | 7.5 (v3.1) | High |
| CVE-2023-6750 | WordPress WP Clone <= 2.4.2 - Database Backup Exposure | clone | 7.5 (v3.1) | High |
| CVE-2024-12008 | W3 Total Cache < 2.8.2 - Log File Exposure | w3 total cache | 7.5 (v3.1) | High |
| CVE-2024-20440 | Cisco Smart Licensing Utility UnAuthenticated Logs Exposure Leaking Plaintext Credentials | smart license utility | 7.5 (v3.1) | High |
| CVE-2024-36991 | Splunk Enterprise - Local File Inclusion | splunk | 7.5 (v3.1) | High |
| CVE-2024-6049 | Lawo AG vsm LTC Time Sync (vTimeSync) - Path Traversal | vsm LTC Time Sync (vTimeSync) | 7.5 (v3.1) | High |
| CVE-2025-14437 | WordPress Hummingbird <= 3.18.0 - Sensitive Information Exposure via Log File | hummingbird-performance | 7.5 (v3.1) | High |
| CVE-2025-31125 | Vite Development Server - Path Traversal | vite | 7.5 (v3.1) | High |
| CVE-2026-28414 | Gradio - Absolute Path Traversal | gradio | 7.5 (v3.1) | High |
| CVE-2017-9416 | Odoo 8.0/9.0/10.0 - Local File Inclusion | odoo | 6.5 (v3.0) | Medium |
| CVE-2018-18762 | SaltOS Erp Crm 3.1 r8126 - Database File Download | saltos | 6.5 (v3.0) | Medium |
| CVE-2026-12898 | All-in-One WP Migration and Backup < 7.106 - Arbitrary Log File Write | all-in-one-wp-migration | 6.5 (v3.1) | Medium |
| CVE-2019-17504 | Kirona-DRS 5.5.3.5 - Information Disclosure | dynamic resource scheduling | 6.1 (v3.1) | Medium |
| CVE-2018-1271 | Spring MVC Framework - Local File Inclusion | spring framework | 5.9 (v3.1) | Medium |
| CVE-2021-40149 | Reolink E1 Zoom Camera <=3.0.0.716 - Private Key Disclosure | e1 zoom | 5.9 (v3.1) | Medium |
| CVE-2024-13609 | WordPress 1 Click Migration Plugin < 2.3 - Information Exposure | 1 click migration | 5.9 (v3.1) | Medium |
| CVE-2017-9965 | Schneider Electric Pelco VideoXpert Enterprise 2.0 - Path Traversal | pelco videoxpert | 5.8 (v3.0) | Medium |
| CVE-2018-16133 | Cybrotech CyBroHttpServer 1.0.3 - Directory Traversal | cybrohttpserver | 5.3 (v3.0) | Medium |
| CVE-2019-17503 | Kirona-DRS 5.5.3.5 - Information Disclosure | dynamic resource scheduling | 5.3 (v3.1) | Medium |
| CVE-2022-25356 | Alt-n/MDaemon Security Gateway <=8.5.0 - XML Injection | securitygateway | 5.3 (v3.1) | Medium |
| CVE-2024-8852 | All-in-One WP Migration < 7.87 - Unauthenticated Information Disclosure | all-in-one wp migration | 5.3 (v3.1) | Medium |
| CVE-2025-32257 | 1 Click WordPress Migration <= 2.2 - Unauthenticated Information Disclsoure | 1-click-migration | 5.3 (v3.1) | Medium |
| CVE-2025-9985 | Featured Image from URL (FIFU) <= 5.2.7 - Unauthenticated Information Exposure via Log File | Featured Image from URL (FIFU) | 5.3 (v3.1) | Medium |
| CVE-2026-50230 | Lyrion Music Server <= 9.2.0 - Cross-Site Scripting | Lyrion Music Server | 5.1 (v4.0) | Medium |
| CVE-2001-1341 | Solare Datensysteme Solar-Log Devices 2.8.4-56/3.5.2-85 - Multiple Vulnerabilities | ipc at chip embedded-webserver | 5.0 (v2.0) | Medium |
| CVE-2022-40843 | Tenda AC1200 V-W15Ev2 - Authentication Bypass | ac1200 v-w15ev2 | 4.9 (v3.1) | Medium |
| CVE-2008-1547 | Microsoft OWA Exchange Server 2003 - 'redir.asp' Open Redirection | exchange server | 4.3 (v2.0) | Medium |
Observed CWEs
These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.