On this page

Atomicorp WAF Rule 390720

Rule Summary

  • Rule ID: 390720
  • Status: Active
  • Alert message: Atomicorp.com WAF Rules: Possible Impedence Mismatch attack on PHP appliction using space to start argument name
  • Observed CWEs: CWE-22 (3), CWE-79 (2), CWE-89 (3), CWE-98 (1), CWE-200 (1), CWE-284 (1)
  • Revision: 6
  • Rule severity: Alert (1)
  • Phase: 2 (request body)
  • Request surfaces: Request filename
  • Rule action: deny
  • HTTP status: 403
  • Public tags: no_ar
  • Logging: log, auditlog

Description

This rule detects behavior identified by its current alert as “Possible Impedence Mismatch attack on PHP appliction using space to start argument name” in the request filename. It evaluates during the request body phase and denies matching traffic with HTTP status 403.

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

CVEVulnerabilityProductCVSSSeverity
CVE-2014-9148Fiyo CMS 2.0.1.8 - Multiple Vulnerabilitiesfiyo cms9.8 (v3.0)Critical
CVE-2015-3933GeniXCMS 0.0.3 - 'register.php' SQL Injectiongenixcms9.8 (v3.0)Critical
CVE-2024-9193WHMpress <= 6.3-revision-0 - Unauthenticated Local File Inclusion to Arbitrary Options Updatewhmcs9.8 (v3.1)Critical
CVE-2014-9145Fiyo CMS 2.0.1.8 - Multiple Vulnerabilitiesfiyo cms7.5 (v2.0)High
CVE-2014-9147Fiyo CMS 2.0.1.8 - Multiple Vulnerabilitiesfiyo cms7.5 (v3.0)High
CVE-2015-2824WordPress Plugin Simple Ads Manager - Multiple SQL Injectionssimple ads manager7.5 (v2.0)High
CVE-2018-15535Responsive FileManager < 9.13.4 - Directory Traversalresponsive filemanager7.5 (v3.0)High
CVE-2022-38467CRM Perks Forms < 1.1.1 - Cross Site Scriptingcrm perks forms6.1 (v3.1)Medium
CVE-2018-15536Responsive FileManager < 9.13.4 - Directory Traversalresponsive filemanager5.5 (v3.0)Medium
CVE-2014-9146Fiyo CMS 2.0.1.8 - Multiple Vulnerabilitiesfiyo cms4.3 (v2.0)Medium
CVE-2014-1222Fiyo CMS 2.0.1.8 - Multiple Vulnerabilitiesvtiger crm4.0 (v2.0)Medium

Observed CWEs

These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.

CWERelated Published CVEs
CWE-22CVE-2018-15535 , CVE-2018-15536 , CVE-2014-1222
CWE-79CVE-2022-38467 , CVE-2014-9146
CWE-89CVE-2015-3933 , CVE-2014-9145 , CVE-2015-2824
CWE-98CVE-2024-9193
CWE-200CVE-2014-9147
CWE-284CVE-2014-9148