On this page
Atomicorp WAF Rule 390801
Rule Summary
- Rule ID: 390801
- Status: Active
- Alert message: Atomicorp.com WAF Rules: Possible Shellkit attack: Generic Attempt to insert shell code
- Observed CWEs: CWE-22 (1), CWE-95 (1), CWE-1286 (1)
- Revision: 5
- Rule severity: Critical (2)
- Request surfaces: Request URI, Request arguments, JSON request data, SOAP request data
- Rule action: deny
- HTTP status: 403
- Logging: log, auditlog
Description
This rule detects behavior identified by its current alert as “Possible Shellkit attack: Generic Attempt to insert shell code” in the request URI, request arguments, JSON request data, SOAP request data. denies matching traffic with HTTP status 403.
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
| CVE | Vulnerability | Product | CVSS | Severity |
|---|---|---|---|---|
| CVE-2019-7194 | QNAP Photo Station < 6.0.3 - Remote Code Execution | photo station | 9.8 (v3.1) | Critical |
| CVE-2024-7954 | SPIP Porte Plume Plugin - Remote Code Execution | SPIP | 9.8 (v3.1) | Critical |
Observed CWEs
These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.
| CWE | Related Published CVEs |
|---|---|
| CWE-22 | CVE-2019-7194 |
| CWE-95 | CVE-2024-7954 |
| CWE-1286 | CVE-2024-7954 |