On this page
Atomicorp WAF Rule 392301
Rule Summary
- Rule ID: 392301
- Status: Active
- Alert message: Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header
- Observed CWEs: CWE-20 (14), CWE-22 (25), CWE-29 (1), CWE-36 (1), CWE-44 (1), CWE-74 (4), CWE-77 (5), CWE-78 (16), CWE-79 (38), CWE-89 (35), CWE-91 (1), CWE-94 (3), CWE-116 (1), CWE-119 (3), CWE-189 (1), CWE-200 (13), CWE-255 (3), CWE-264 (3), CWE-269 (2), CWE-284 (4), CWE-285 (2), CWE-287 (10), CWE-288 (1), CWE-303 (1), CWE-306 (3), CWE-310 (2), CWE-312 (1), CWE-319 (1), CWE-327 (1), CWE-352 (4), CWE-362 (1), CWE-420 (1), CWE-425 (1), CWE-434 (10), CWE-444 (2), CWE-502 (3), CWE-522 (1), CWE-601 (4), CWE-611 (2), CWE-639 (2), CWE-706 (1), CWE-770 (1), CWE-787 (2), CWE-798 (5), CWE-862 (1), CWE-863 (1), CWE-918 (11), CWE-1021 (1), CWE-1336 (1), CWE-1390 (1)
- Revision: 8
- Rule severity: Notice (5)
- Phase: 2 (request body)
- Request surfaces: Request headers
- Rule action: deny
- HTTP status: 403
- Public tags: no_ar
- Logging: log, auditlog
Description
This rule detects when a request is made using an improper method. By default, if a request body is sent it must define its Content-Type so the backend application knows how to handle it. The WAF also needs to understand the Content-Type. he WAF works by inspecting content based on the “type” defined by the request. This of this as a foreign language. The WAF needs to understand the type to be able to properly inspect its contents.
Attacks use this method to get past WAFs by not defining the Content-Type, so the WAF has to guess what its reading. The attacker relies on this and that the WAF will assume its reading one content type, when another content type is being used. This can be used to bypass the WAF entirely.
This rule prevents this method. Any application that causes this to occur should be fixed to define its Content-Type.
False Positives
A false positive can occur when an application legitimately does not set the Content-Type. However, this should never be allowed. All request bodies should define the Content-Type, and there is no reason for an application to not do this. We highly recommend you do not disable this rule, and rather fix the application.
If you believe this is a false positive, that is the application is defining a Content-Type, please report this to our security team to determine if this is a legitimate case, or if its clever attack on your system. Instructions to report false positives are detailed on the Reporting False Positives wiki page. If it is a false positive, we will fix the issue in the rules and get a release out to you promptly.
Tuning Guidance
If you know that this behaviour is acceptable for your application, please see the Tuning the Atomicorp WAF Rules page for basic information.
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
| CVE | Vulnerability | Product | CVSS | Severity |
|---|---|---|---|---|
| CVE-2014-8877 | WordPress Plugin CM Download Manager 2.0.0 - Code Injection | cm download manager | 10.0 (v2.0) | High |
| CVE-2022-22536 | SAP Memory Pipes (MPI) Desynchronization | content server | 10.0 (v3.1) | Critical |
| CVE-2024-10081 | CodeChecker <= 6.24.1 - Authentication Bypass | codechecker | 10.0 (v3.1) | Critical |
| CVE-2024-4040 | CrushFTP VFS - Sandbox Escape LFR | crushftp | 10.0 (v3.1) | Critical |
| CVE-2024-46506 | NetAlertX 23.01.14–24.x < 24.10.12 - Remote Code Execution | netalertx | 10.0 (v3.1) | Critical |
| CVE-2025-20281 | Cisco ISE - Remote Code Execution | identity services engine | 10.0 (v3.1) | Critical |
| CVE-2019-4013 | IBM Bigfix Platform 9.5.9.62 - Arbitrary File Upload | bigfix platform | 9.9 (v3.0) | Critical |
| CVE-2012-1259 | Scrutinizer NetFlow & sFlow Analyzer - Multiple Vulnerabilities | scrutinizer netflow & sflow analyzer | 9.8 (v3.1) | Critical |
| CVE-2013-2681 | Cisco Linksys E4200 - Multiple Vulnerabilities | linksys e4200 firmware | 9.8 (v3.1) | Critical |
| CVE-2013-7137 | Burden 1.8 - Authentication Bypass | burden | 9.8 (v3.1) | Critical |
| CVE-2014-9614 | Netsweeper 4.0.5 - Default Weak Account | netsweeper | 9.8 (v3.1) | Critical |
| CVE-2015-4664 | Xceedium Xsuite - Multiple Vulnerabilities | privileged access manager | 9.8 (v3.0) | Critical |
| CVE-2015-4667 | Xceedium Xsuite - Multiple Vulnerabilities | xsuite | 9.8 (v3.0) | Critical |
| CVE-2015-4683 | Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilities | realpresence resource manager | 9.8 (v3.0) | Critical |
| CVE-2015-6970 | Bosch Security Systems Dinion NBN-498 - Web Interface XML Injection | nbn-498 dinion2x day/night ip cameras firmware | 9.8 (v3.1) | Critical |
| CVE-2016-3088 | Apache ActiveMQ Fileserver - Arbitrary File Write | activemq | 9.8 (v3.1) | Critical |
| CVE-2016-5674 | NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilities | readynas surveillance | 9.8 (v3.0) | Critical |
| CVE-2016-5675 | NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilities | readynas surveillance | 9.8 (v3.0) | Critical |
| CVE-2016-5678 | NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilities | nvrmini 2 | 9.8 (v3.0) | Critical |
| CVE-2016-6600 | WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilities | webnms framework | 9.8 (v3.0) | Critical |
| CVE-2016-6602 | WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilities | webnms framework | 9.8 (v3.0) | Critical |
| CVE-2016-6603 | WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilities | webnms framework | 9.8 (v3.0) | Critical |
| CVE-2016-9682 | Sonicwall Secure Remote Access 8.1.0.2-14sv - Command Injection | sonicwall secure remote access server | 9.8 (v3.0) | Critical |
| CVE-2017-10366 | Oracle PeopleSoft 8.5x - Remote Code Execution | peoplesoft enterprise peopletools | 9.8 (v3.0) | Critical |
| CVE-2017-12635 | Apache CouchDB 1.7.0 / 2.x < 2.1.1 - Remote Privilege Escalation | couchdb | 9.8 (v3.0) | Critical |
| CVE-2017-17970 | Muviko 1.1 - SQL Injection | muviko | 9.8 (v3.0) | Critical |
| CVE-2017-17976 | PerfexCRM 1.9.7 - Arbitrary File Upload | perfex crm | 9.8 (v3.0) | Critical |
| CVE-2018-10562 | Dasan GPON Devices - Remote Code Execution | gpon router firmware | 9.8 (v3.1) | Critical |
| CVE-2018-12596 | Ektron CMS 9.20 SP2 - Improper Access Restrictions | ektron cms | 9.8 (v3.0) | Critical |
| CVE-2018-14728 | Responsive filemanager 9.13.1 Server-Side Request Forgery | responsive filemanager | 9.8 (v3.0) | Critical |
| CVE-2018-15534 | Geutebrueck re_porter 7.8.974.20 - Credential Disclosure | re porter 16 firmware | 9.8 (v3.0) | Critical |
| CVE-2018-20985 | WordPress Payeezy Pay <=2.97 - Local File Inclusion | wp payeezy pay | 9.8 (v3.0) | Critical |
| CVE-2018-9160 | SickRage < v2018.03.09 - Clear-Text Credentials HTTP Response | sickrage | 9.8 (v3.0) | Critical |
| CVE-2019-16278 | nostromo 1.9.6 - Remote Code Execution | nostromo nhttpd | 9.8 (v3.1) | Critical |
| CVE-2019-1935 | Cisco UCS Director_ Cisco Integrated Management Controller Supervisor and Cisco UCS Director Express for Big Data - Multiple Vulnerabilities | integrated management controller supervisor | 9.8 (v3.1) | Critical |
| CVE-2019-1937 | Cisco UCS Director_ Cisco Integrated Management Controller Supervisor and Cisco UCS Director Express for Big Data - Multiple Vulnerabilities | integrated management controller supervisor | 9.8 (v3.0) | Critical |
| CVE-2019-19740 | Octeth Oempro 4.8 - 'CampaignID' SQL Injection | oempro | 9.8 (v3.1) | Critical |
| CVE-2019-3396 | Atlassian Confluence Server - Path Traversal | confluence | 9.8 (v3.1) | Critical |
| CVE-2020-17463 | Fuel CMS 1.4.7 - 'col' SQL Injection (Authenticated) | fuel cms | 9.8 (v3.1) | Critical |
| CVE-2020-25506 | D-Link DNS-320 - Unauthenticated Remote Code Execution | dns-320 firmware | 9.8 (v3.1) | Critical |
| CVE-2020-26919 | NETGEAR ProSAFE Plus - Unauthenticated Remote Code Execution | jgs516pe firmware | 9.8 (v3.1) | Critical |
| CVE-2020-35713 | Belkin Linksys RE6500 <1.0.012.001 - Remote Command Execution | re6500 firmware | 9.8 (v3.1) | Critical |
| CVE-2020-35729 | Klog Server <=2.41 - Unauthenticated Command Injection | klog server | 9.8 (v3.1) | Critical |
| CVE-2020-5902 | F5 BIG-IP TMUI - Remote Code Execution | big-ip access policy manager | 9.8 (v3.1) | Critical |
| CVE-2020-8515 | Multiple DrayTek Products - Pre-authentication Remote Root Code Execution | vigor2960 firmware | 9.8 (v3.1) | Critical |
| CVE-2020-8771 | WordPress Time Capsule < 1.21.16 - Authentication Bypass | wp time capsule | 9.8 (v3.1) | Critical |
| CVE-2021-20158 | Trendnet AC2600 TEW-827DRU 2.08B01 - Admin Password Change | tew-827dru firmware | 9.8 (v3.1) | Critical |
| CVE-2021-30118 | Kaseya VSA < 9.5.7 - Arbitrary File Upload to Remote Code Execution | vsa | 9.8 (v3.1) | Critical |
| CVE-2021-36380 | Sunhillo SureLine <8.7.0.1.1 - Unauthenticated OS Command Injection | sureline | 9.8 (v3.1) | Critical |
| CVE-2021-40617 | openSIS Community Edition 8.0 - SQL Injection | opensis | 9.8 (v3.1) | Critical |
| CVE-2021-41649 | PuneethReddyHC Online Shopping System homeaction.php SQL Injection | online-shopping-system-advanced | 9.8 (v3.1) | Critical |
| CVE-2021-4449 | ZoomSounds Plugin - Unauthenticated Arbitrary File Upload | zoomsounds | 9.8 (v3.1) | Critical |
| CVE-2021-44567 | RosarioSIS 7.6 - SQL Injection | rosariosis | 9.8 (v3.1) | Critical |
| CVE-2021-45382 | D-Link - Remote Command Execution | dir-820l firmware | 9.8 (v3.1) | Critical |
| CVE-2021-45428 | Telesquare TLR-2005KSH 1.0.0 - Arbitrary File Upload | tlr-2005ksh | 9.8 (v3.1) | Critical |
| CVE-2022-0332 | Moodle 3.11.4 - SQL Injection | moodle | 9.8 (v3.1) | Critical |
| CVE-2022-29013 | Razer Sila Gaming Router - Remote Code Execution | sila | 9.8 (v3.1) | Critical |
| CVE-2022-34128 | GLPI Cartography Plugin v6.0.0 - Unauthenticated Remote Code Execution (RCE) | positions | 9.8 (v3.1) | Critical |
| CVE-2022-35405 | Zoho ManageEngine - Remote Code Execution | manageengine access manager plus | 9.8 (v3.1) | Critical |
| CVE-2022-36446 | Webmin <1.997 - Authenticated Remote Code Execution | webmin | 9.8 (v3.1) | Critical |
| CVE-2022-38580 | X-Skipper-Proxy v0.13.237 - Server Side Request Forgery (SSRF) | skipper | 9.8 (v3.1) | Critical |
| CVE-2022-48323 | Sunflower Simple and Personal 1.0.1.43315 - Remote Code Execution | sunflower | 9.8 (v3.1) | Critical |
| CVE-2023-0938 | Music Gallery Site v1.0 - SQL Injection on music_list.php | music gallery site | 9.8 (v3.1) | Critical |
| CVE-2023-22463 | KubePi JwtSigKey - Admin Authentication Bypass | kubepi | 9.8 (v3.1) | Critical |
| CVE-2023-30013 | TOTOLink - Unauthenticated Command Injection | x5000r firmware | 9.8 (v3.1) | Critical |
| CVE-2023-33362 | Piwigo 13.6.0 - SQL Injection | piwigo | 9.8 (v3.1) | Critical |
| CVE-2023-34048 | VMware vCenter Server - Out-of-Bounds Write | vcenter server | 9.8 (v3.1) | Critical |
| CVE-2023-3722 | Avaya Aura Device Services - OS Command Injection | aura device services | 9.8 (v3.1) | Critical |
| CVE-2023-41109 | SmartNode SN200 Analog Telephone Adapter (ATA) & VoIP Gateway - Command Injection | smartnode sn200 | 9.8 (v3.1) | Critical |
| CVE-2023-46574 | TOTOLINK A3700R - Command Injection | a3700r firmware | 9.8 (v3.1) | Critical |
| CVE-2023-48022 | Anyscale Ray - Remote Code Execution | ray | 9.8 (v3.1) | Critical |
| CVE-2024-22729 | Netis MW5360 V1.0.1.3031 - Command Injection | mw5360 firmware | 9.8 (v3.1) | Critical |
| CVE-2024-24328 | TotoLink Router setMacFilterRules - Command Injection | a3300r firmware | 9.8 (v3.1) | Critical |
| CVE-2024-24329 | TotoLink Router setPortForwardRules - Command Injection | a3300r firmware | 9.8 (v3.1) | Critical |
| CVE-2024-24495 | Daily Habit Tracker 1.0 - SQL Injection | daily habit tracker | 9.8 (v3.1) | Critical |
| CVE-2024-34257 | TOTOLINK EX1800T TOTOLINK EX1800T - Command Injection | a3700r firmware | 9.8 (v3.1) | Critical |
| CVE-2024-3922 | Dokan Pro <= 3.10.3 - SQL Injection | dokan | 9.8 (v3.1) | Critical |
| CVE-2024-4577 | PHP CGI - Argument Injection | php | 9.8 (v3.1) | Critical |
| CVE-2024-7593 | Ivanti vTM - Authentication Bypass | virtual traffic manager | 9.8 (v3.1) | Critical |
| CVE-2025-24813 | Apache Tomcat Path Equivalence - Remote Code Execution | tomcat | 9.8 (v3.1) | Critical |
| CVE-2025-40552 | SolarWinds Web Help Desk - Authentication Bypass | web help desk | 9.8 (v3.1) | Critical |
| CVE-2026-35616 | FortiClient EMS - Authentication Bypass | forticlient ems | 9.8 (v3.1) | Critical |
| CVE-2017-14611 | Cockpit CMS 0.4.4 < 0.5.5 - Server-Side Request Forgery | cockpit | 9.1 (v3.0) | Critical |
| CVE-2018-9302 | Cockpit CMS 0.4.4 < 0.5.5 - Server-Side Request Forgery | cockpit | 9.1 (v3.0) | Critical |
| CVE-2021-27828 | In4Suit ERP 3.2.74.1370 - 'txtLoginId' SQL injection | in4suite erp | 9.1 (v3.1) | Critical |
| CVE-2021-27931 | LumisXP <10.0.0 - Blind XML External Entity Attack | lumis experience platform | 9.1 (v3.1) | Critical |
| CVE-2021-37593 | PEEL Shopping 9.3.0 - 'id' Time-based SQL Injection | peel shopping | 9.1 (v3.1) | Critical |
| CVE-2021-46419 | Telesquare TLR-2855KS6 - Arbitrary File Deletion | tlr-2855ks6 firmware | 9.1 (v3.1) | Critical |
| CVE-2026-54157 | LobeHub LobeChat <= 2.1.56 - Server-Side Request Forgery | lobe-chat | 9.0 (v3.1) | Critical |
| CVE-2014-8356 | ZHONE < S3.0.501 - Multiple Vulnerabilities | znid 2426a firmware | 8.8 (v3.1) | High |
| CVE-2014-8357 | ZHONE < S3.0.501 - Multiple Vulnerabilities | znid 2426a firmware | 8.8 (v3.0) | High |
| CVE-2014-9118 | ZHONE < S3.0.501 - Multiple Vulnerabilities | znid 2426a firmware | 8.8 (v3.0) | High |
| CVE-2015-0104 | IBM Tivoli Service Automation Manager 7.2.4 - Remote Code Execution | change and configuration management database | 8.8 (v3.0) | High |
| CVE-2016-10960 | WordPress wSecure Lite < 2.4 - Remote Code Execution | wsecure | 8.8 (v3.1) | High |
| CVE-2016-5679 | NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilities | nvrmini 2 | 8.8 (v3.0) | High |
| CVE-2016-5680 | NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilities | nvrmini 2 | 8.8 (v3.0) | High |
| CVE-2017-5799 | HPE OpenCall Media Platform (OCMP) 4.3.2 - Cross-Site Scripting / Remote File Inclusion | opencall media platform | 8.8 (v3.0) | High |
| CVE-2017-9413 | Subsonic 6.1.1 - Server-Side Request Forgery | subsonic | 8.8 (v3.0) | High |
| CVE-2018-5406 | KACE System Management Appliance (SMA) < 9.0.270 - Multiple Vulnerabilities | kace systems management appliance firmware | 8.8 (v3.1) | High |
| CVE-2020-24579 | D-Link DSL 2888a - Authentication Bypass/Remote Command Execution | dsl2888a firmware | 8.8 (v3.1) | High |
| CVE-2020-25760 | Visitor Management System in PHP 1.0 - SQL Injection (Authenticated) | visitor management system | 8.8 (v3.1) | High |
| CVE-2020-5192 | Hospital Management System 4.0 - 'searchdata' SQL Injection | hospital management system | 8.8 (v3.1) | High |
| CVE-2020-5504 | phpMyAdmin 5.0.0 - SQL Injection | phpmyadmin | 8.8 (v3.1) | High |
| CVE-2021-28151 | Hongdian H8922 3.0.5 - Remote Command Injection | h8922 firmware | 8.8 (v3.1) | High |
| CVE-2023-0962 | Music Gallery Site v1.0 - SQL Injection on page Master.php | music gallery site | 8.8 (v3.1) | High |
| CVE-2023-30625 | Rudder Server < 1.3.0-rc.1 - SQL Injection | rudder-server | 8.8 (v3.1) | High |
| CVE-2023-4169 | Ruijie RG-EW1200G Router - Password Reset | rg-ew1200g firmware | 8.8 (v3.1) | High |
| CVE-2023-4415 | Ruijie RG-EW1200G Router Background - Login Bypass | rg-ew1200g firmware | 8.8 (v3.1) | High |
| CVE-2023-49230 | Peplink Balance Two before 8.4.0 - Unauthenticated Config Upload | balance two firmware | 8.8 (v3.1) | High |
| CVE-2024-24919 | Check Point Quantum Gateway - Information Disclosure | quantum security gateway | 8.6 (v3.1) | High |
| CVE-2024-9054 | Microchip TimeProvider 4100 (Configuration modules) 2.4.6 - OS Command Injection | timeprovider 4100 firmware | 8.5 (v4.0) | High |
| CVE-2024-21893 | Ivanti SAML - Server Side Request Forgery (SSRF) | connect secure | 8.2 (v3.1) | High |
| CVE-2013-2678 | Cisco Linksys E4200 - Multiple Vulnerabilities | linksys e4200 firmware | 8.1 (v3.1) | High |
| CVE-2016-1337 | Cisco EPC 3928 - Multiple Vulnerabilities | epc3928 firmware | 8.1 (v3.0) | High |
| CVE-2017-12615 | Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution (1) | tomcat | 8.1 (v3.1) | High |
| CVE-2017-12617 | Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution (1) | tomcat | 8.1 (v3.1) | High |
| CVE-2018-11231 | Opencart Divido - Sql Injection | divido | 8.1 (v3.0) | High |
| CVE-2019-6340 | Drupal - Remote Code Execution | drupal | 8.1 (v3.1) | High |
| CVE-2023-26067 | Lexmark Printers - Command Injection | cxtpc firmware | 8.1 (v3.1) | High |
| CVE-2021-20167 | Netgear RAX43 1.0.3.96 - Command Injection/Authentication Bypass Buffer Overrun | rax43 firmware | 8.0 (v3.1) | High |
| CVE-2015-4669 | Xceedium Xsuite - Multiple Vulnerabilities | xsuite | 7.8 (v3.0) | High |
| CVE-2015-4681 | Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilities | realpresence resource manager | 7.8 (v3.0) | High |
| CVE-2023-46022 | Blood Bank 1.0 - 'bid' SQLi | blood bank | 7.8 (v3.1) | High |
| CVE-2016-3473 | Oracle BI Publisher 11.1.1.6.0/11.1.1.7.0/11.1.1.9.0/12.2.1.0.0 - XML External Entity Injection | business intelligence publisher | 7.7 (v3.0) | High |
| CVE-2024-43687 | Microchip TimeProvider 4100 Grandmaster (Banner Config Modules) 2.4.6 - Stored Cross-Site Scripting (XSS) | timeprovider 4100 firmware | 7.7 (v4.0) | High |
| CVE-2011-4899 | WordPress Core 3.3.1 - Multiple Vulnerabilities | WordPress | 7.5 (v2.0) | High |
| CVE-2013-0249 | cURL - Buffer Overflow (PoC) | curl | 7.5 (v2.0) | High |
| CVE-2013-2680 | Cisco Linksys E4200 - Multiple Vulnerabilities | linksys e4200 firmware | 7.5 (v3.1) | High |
| CVE-2013-5639 | Gnew 2013.1 - Multiple Vulnerabilities (2) | gnew | 7.5 (v2.0) | High |
| CVE-2013-5640 | Gnew 2013.1 - Multiple Vulnerabilities (2) | gnew | 7.5 (v2.0) | High |
| CVE-2013-6164 | Project'Or RIA 3.4.0 - 'objectDetail.php?objectId' SQL Injection | projeqtor | 7.5 (v2.0) | High |
| CVE-2014-3704 | Drupal SQL Injection | drupal | 7.5 (v2.0) | High |
| CVE-2014-6389 | PHPCompta/NOALYSS 6.7.1 5638 - Remote Command Execution | phpcompta/noalyss | 7.5 (v2.0) | High |
| CVE-2014-9464 | Microweber CMS 0.95 - SQL Injection | microweber | 7.5 (v2.0) | High |
| CVE-2015-1503 | IceWarp Mail Server < 11.1.1 - Directory Traversal | mail server | 7.5 (v3.0) | High |
| CVE-2015-6401 | Cisco EPC 3928 - Multiple Vulnerabilities | epc3928 docsis 3.0 8x4 wireless residential gateway with embedded digital voice adapter | 7.5 (v2.0) | High |
| CVE-2015-7245 | D-Link DVG-N5402SP - Local File Inclusion | dvg-n5402sp firmware | 7.5 (v3.0) | High |
| CVE-2016-1328 | Cisco EPC 3928 - Multiple Vulnerabilities | epc3928 firmware | 7.5 (v3.0) | High |
| CVE-2016-1336 | Cisco EPC 3928 - Multiple Vulnerabilities | epc3928 firmware | 7.5 (v3.0) | High |
| CVE-2016-4309 | Symphony CMS 2.6.7 - Session Fixation | symphony | 7.5 (v3.1) | High |
| CVE-2016-5676 | NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilities | readynas surveillance | 7.5 (v3.0) | High |
| CVE-2016-5677 | NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilities | readynas surveillance | 7.5 (v3.0) | High |
| CVE-2016-6601 | WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilities | webnms framework | 7.5 (v3.0) | High |
| CVE-2017-1000170 | WordPress Delightful Downloads Jquery File Tree 2.1.5 - Local File Inclusion | jqueryfiletree | 7.5 (v3.1) | High |
| CVE-2017-14523 | Wonder CMS 2.3.1 - 'Host' Header Injection | wondercms | 7.5 (v3.0) | High |
| CVE-2017-5850 | OpenBSD HTTPd < 6.0 - Memory Exhaustion Denial of Service | openbsd | 7.5 (v3.0) | High |
| CVE-2018-15535 | Responsive FileManager < 9.13.4 - Directory Traversal | responsive filemanager | 7.5 (v3.0) | High |
| CVE-2018-7171 | TwonkyMedia Server 7.0.11-8.5 - Directory Traversal | twonky server | 7.5 (v3.0) | High |
| CVE-2021-41293 | ECOA Building Automation System - Arbitrary File Retrieval | ecs router controller-ecs firmware | 7.5 (v3.1) | High |
| CVE-2021-41648 | PuneethReddyHC action.php SQL Injection | online-shopping-system-advanced | 7.5 (v3.1) | High |
| CVE-2021-46381 | DLINK DAP-1620 A1 v1.01 - Directory Traversal | dap-1620 firmware | 7.5 (v3.1) | High |
| CVE-2021-46418 | Telesquare TLR-2855KS6 - Arbitrary File Creation | tlr-2855ks6 | 7.5 (v3.1) | High |
| CVE-2023-40279 | OpenClinic GA 5.247.01 - Path Traversal (Authenticated) | openclinic ga | 7.5 (v3.1) | High |
| CVE-2023-6909 | Mlflow <2.9.2 - Path Traversal | mlflow | 7.5 (v3.1) | High |
| CVE-2024-37393 | SecurEnvoy Two Factor Authentication - LDAP Injection | multi-factor authentication solutions | 7.5 (v3.1) | High |
| CVE-2024-6250 | LOLLMS WebUI - Absolute Path Traversal | lollms web ui | 7.5 (v3.0) | High |
| CVE-2017-15643 | Ikraus Anti Virus 2.16.7 - Remote Code Execution | ikarus antivirus | 7.4 (v3.0) | High |
| CVE-2017-9355 | Subsonic 6.1.1 - XML External Entity Injection | subsonic | 7.4 (v3.0) | High |
| CVE-2010-4297 | VMware Tools - Update OS Command Injection | workstation | 7.2 (v2.0) | High |
| CVE-2019-1936 | Cisco UCS Director_ Cisco Integrated Management Controller Supervisor and Cisco UCS Director Express for Big Data - Multiple Vulnerabilities | integrated management controller supervisor | 7.2 (v3.1) | High |
| CVE-2020-20969 | PluckCMS 4.7.10 - Unrestricted File Upload | pluck | 7.2 (v3.1) | High |
| CVE-2023-33629 | H3C Magic R300-2100M - Remote Code Execution | magic r300-2100m firmware | 7.2 (v3.1) | High |
| CVE-2018-1247 | RSA Authentication Manager 8.2.1.4.0-build1394922 / < 8.3 P1 - XML External Entity Injection / Cross-Site Flashing / DOM Cross-Site Scripting | authentication manager | 7.1 (v3.0) | High |
| CVE-2015-4685 | Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilities | realpresence resource manager | 7.0 (v3.0) | High |
| CVE-2024-7339 | TVT DVR Sensitive Device - Information Disclosure | sh-4050a5-5l(mm) firmware | 6.9 (v4.0) | Medium |
| CVE-2012-0286 | stoneware webnetwork6 - Multiple Vulnerabilities | webnetwork | 6.8 (v2.0) | Medium |
| CVE-2012-3350 | Webmatic 3.1.1 - Blind SQL Injection | webmatic | 6.8 (v2.0) | Medium |
| CVE-2014-0864 | IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilities | algo credit limits | 6.8 (v2.0) | Medium |
| CVE-2015-5161 | Zend Framework 2.4.2 - PHP FPM XML eXternal Entity Injection | zend framework | 6.8 (v2.0) | Medium |
| CVE-2012-1258 | Scrutinizer NetFlow & sFlow Analyzer - Multiple Vulnerabilities | scrutinizer netflow & sflow analyzer | 6.5 (v3.1) | Medium |
| CVE-2014-2531 | InterWorx Control Panel 5.0.13 build 574 - 'xhr.php?i' SQL Injection | web control panel | 6.5 (v2.0) | Medium |
| CVE-2014-5462 | OpenEMR 4.1.2(7) - Multiple SQL Injections | openemr | 6.5 (v2.0) | Medium |
| CVE-2014-7176 | Enalean Tuleap 7.4.99.5 - Blind SQL Injection | tuleap | 6.5 (v2.0) | Medium |
| CVE-2015-4682 | Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilities | realpresence resource manager | 6.5 (v3.0) | Medium |
| CVE-2015-4684 | Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilities | realpresence resource manager | 6.5 (v3.0) | Medium |
| CVE-2017-3546 | Oracle PeopleSoft - Server-Side Request Forgery | peoplesoft enterprise peopletools | 6.5 (v3.0) | Medium |
| CVE-2018-5404 | KACE System Management Appliance (SMA) < 9.0.270 - Multiple Vulnerabilities | kace systems management appliance firmware | 6.5 (v3.0) | Medium |
| CVE-2018-7690 | Fortify Software Security Center (SSC) 17.10/17.20/18.10 - Information Disclosure | fortify software security center | 6.5 (v3.0) | Medium |
| CVE-2018-9038 | Monstra CMS 3.0.4 - Arbitrary Folder Deletion | monstra | 6.5 (v3.0) | Medium |
| CVE-2019-12616 | phpMyAdmin 4.8 - Cross-Site Request Forgery | phpmyadmin | 6.5 (v3.0) | Medium |
| CVE-2019-3778 | Spring Security OAuth - Open Redirector | spring security oauth | 6.5 (v3.1) | Medium |
| CVE-2021-34369 | Accela Civic Platform 21.1 - 'contactSeqNumber' Insecure Direct Object References (IDOR) | civic platform | 6.5 (v3.1) | Medium |
| CVE-2023-3188 | Owncast - Server Side Request Forgery | owncast | 6.5 (v3.1) | Medium |
| CVE-2017-9640 | Automated Logic WebCTRL 6.1 - Path Traversal / Arbitrary File Write | i-vu | 6.3 (v3.0) | Medium |
| CVE-2024-7801 | Microchip TimeProvider 4100 Grandmaster (Data plot modules) 2.4.6 - SQL Injection | timeprovider 4100 firmware | 6.3 (v4.0) | Medium |
| CVE-2012-1260 | Scrutinizer NetFlow & sFlow Analyzer - Multiple Vulnerabilities | scrutinizer netflow & sflow analyzer | 6.1 (v3.1) | Medium |
| CVE-2012-1261 | Scrutinizer NetFlow & sFlow Analyzer - Multiple Vulnerabilities | scrutinizer netflow & sflow analyzer | 6.1 (v3.1) | Medium |
| CVE-2013-2679 | Cisco Linksys E4200 - Multiple Vulnerabilities | linksys e4200 firmware | 6.1 (v3.1) | Medium |
| CVE-2013-2684 | Cisco Linksys E4200 - Multiple Vulnerabilities | linksys e4200 firmware | 6.1 (v3.1) | Medium |
| CVE-2015-4668 | Xceedium Xsuite - Multiple Vulnerabilities | xsuite | 6.1 (v3.0) | Medium |
| CVE-2017-17059 | WordPress amtyThumb Posts 8.1.3 - Cross-Site Scripting | amtythumb | 6.1 (v3.0) | Medium |
| CVE-2017-3132 | Fortinet FortiOS < 5.6.0 - Cross-Site Scripting | fortios | 6.1 (v3.0) | Medium |
| CVE-2017-3133 | Fortinet FortiOS < 5.6.0 - Cross-Site Scripting | fortios | 6.1 (v3.0) | Medium |
| CVE-2017-5798 | HPE OpenCall Media Platform (OCMP) 4.3.2 - Cross-Site Scripting / Remote File Inclusion | opencall media platform | 6.1 (v3.0) | Medium |
| CVE-2017-9072 | RSA Authentication Manager 8.2.1.4.0-build1394922 / < 8.3 P1 - XML External Entity Injection / Cross-Site Flashing / DOM Cross-Site Scripting | flatcalendarxp | 6.1 (v3.0) | Medium |
| CVE-2017-9979 | QuantaStor Software Defined Storage < 4.3.1 - Multiple Vulnerabilities | quantastor | 6.1 (v3.0) | Medium |
| CVE-2018-17082 | Apache2 - Transfer-Encoding Chunked XSS | php | 6.1 (v3.0) | Medium |
| CVE-2018-18069 | WordPress sitepress-multilingual-cms 3.6.3 - Cross-Site Scripting | wpml | 6.1 (v3.0) | Medium |
| CVE-2019-18859 | Digi AnywhereUSB 14 - Reflective Cross-Site Scripting | anywhereusb/14 firmware | 6.1 (v3.1) | Medium |
| CVE-2019-1943 | CISCO Small Business 200 / 300 / 500 Switches - Multiple Vulnerabilities | sg200-50 firmware | 6.1 (v3.0) | Medium |
| CVE-2019-9591 | ShoreTel Connect ONSITE < 19.49.1500.0 - Multiple Vulnerabilities | connect onsite | 6.1 (v3.1) | Medium |
| CVE-2019-9592 | ShoreTel Connect ONSITE < 19.49.1500.0 - Multiple Vulnerabilities | connect onsite | 6.1 (v3.1) | Medium |
| CVE-2019-9593 | ShoreTel Connect ONSITE < 19.49.1500.0 - Multiple Vulnerabilities | connect onsite | 6.1 (v3.1) | Medium |
| CVE-2020-25864 | HashiCorp Consul/Consul Enterprise <=1.9.4 - Cross-Site Scripting | consul | 6.1 (v3.1) | Medium |
| CVE-2021-24407 | WordPress Jannah Theme <5.4.5 - Cross-Site Scripting | jannah | 6.1 (v3.1) | Medium |
| CVE-2021-24563 | WordPress Plugin Frontend Uploader 1.3.2 - Stored Cross Site Scripting (XSS) (Unauthenticated) | frontend uploader | 6.1 (v3.1) | Medium |
| CVE-2021-33904 | Accela Civic Platform 21.1 - 'servProvCode' Cross-Site-Scripting (XSS) | civic platform | 6.1 (v3.1) | Medium |
| CVE-2021-34370 | Accela Civic Platform 21.1 - 'successURL' Cross-Site-Scripting (XSS) | civic platform | 6.1 (v3.1) | Medium |
| CVE-2022-30513 | School Dormitory Management System 1.0 - Authenticated Cross-Site Scripting | school dormitory management system | 6.1 (v3.1) | Medium |
| CVE-2022-30514 | School Dormitory Management System 1.0 - Authenticated Cross-Site Scripting | school dormitory management system | 6.1 (v3.1) | Medium |
| CVE-2022-34048 | Wavlink WN-533A8 - Cross-Site Scripting | wn533a8 firmware | 6.1 (v3.1) | Medium |
| CVE-2023-5558 | LearnPress < 4.2.5.5 - Cross-Site Scripting | learnpress | 6.1 (v3.1) | Medium |
| CVE-2024-3378 | iboss Secure Web Gateway - Stored Cross-Site Scripting (XSS) | secure web gateway | 6.1 (v3.1) | Medium |
| CVE-2012-6499 | WordPress Plugin Age Verification v0.4 - Open Redirect | age verification | 5.8 (v2.0) | Medium |
| CVE-2014-0867 | IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilities | algo credit limits | 5.8 (v2.0) | Medium |
| CVE-2018-15536 | Responsive FileManager < 9.13.4 - Directory Traversal | responsive filemanager | 5.5 (v3.0) | Medium |
| CVE-2017-3131 | Fortinet FortiOS < 5.6.0 - Cross-Site Scripting | fortios | 5.4 (v3.0) | Medium |
| CVE-2018-5405 | KACE System Management Appliance (SMA) < 9.0.270 - Multiple Vulnerabilities | kace systems management appliance firmware | 5.4 (v3.0) | Medium |
| CVE-2019-11269 | Spring Security OAuth - Open Redirector | spring security oauth | 5.4 (v3.1) | Medium |
| CVE-2020-7108 | WordPress Plugin LearnDash LMS 3.1.2 - Reflective Cross-Site Scripting | learndash | 5.4 (v3.1) | Medium |
| CVE-2023-4382 | Hyip Rio 2.1 - Arbitrary File Upload | hyip rio | 5.4 (v3.1) | Medium |
| CVE-2013-2683 | Cisco Linksys E4200 - Multiple Vulnerabilities | linksys e4200 firmware | 5.3 (v3.1) | Medium |
| CVE-2017-9978 | QuantaStor Software Defined Storage < 4.3.1 - Multiple Vulnerabilities | quantastor | 5.3 (v3.0) | Medium |
| CVE-2018-16059 | WirelessHART Fieldgate SWG70 3.0 - Local File Inclusion | wirelesshart fieldgate swg70 firmware | 5.3 (v3.0) | Medium |
| CVE-2018-3167 | Oracle E-Business Suite - Blind SSRF | application management pack | 5.3 (v3.0) | Medium |
| CVE-2019-14430 | YouPHPTube 7.2 - 'userCreate.json.php' SQL Injection | youphptube | 5.3 (v3.0) | Medium |
| CVE-2019-8446 | Jira Improper Authorization | jira server | 5.3 (v3.1) | Medium |
| CVE-2021-20150 | Trendnet AC2600 TEW-827DRU - Credentials Disclosure | tew-827dru firmware | 5.3 (v3.1) | Medium |
| CVE-2021-26085 | Atlassian Confluence 7.12.2 - Pre-Authorization Arbitrary File Read | confluence data center | 5.3 (v3.1) | Medium |
| CVE-2021-26086 | Atlassian Jira Server Data Center 8.16.0 - Arbitrary File Read | jira data center | 5.3 (v3.1) | Medium |
| CVE-2022-28666 | Custom Product Tabs for WooCommerce < 1.7.8 - Unauthenticated Toggle Content Setting Update | custom product tabs for woocommerce | 5.3 (v3.1) | Medium |
| CVE-2024-20404 | Cisco Finesse - Server-Side Request Forgery (SSRF) | finesse | 5.3 (v3.1) | Medium |
| CVE-2000-0114 | Microsoft FrontPage Extensions - Information Disclosure | internet information server | 5.0 (v2.0) | Medium |
| CVE-2001-1341 | Solare Datensysteme Solar-Log Devices 2.8.4-56/3.5.2-85 - Multiple Vulnerabilities | ipc at chip embedded-webserver | 5.0 (v2.0) | Medium |
| CVE-2006-3835 | toutvirtual virtualiq pro 3.2 - Multiple Vulnerabilities | tomcat | 5.0 (v2.0) | Medium |
| CVE-2010-3486 | SmarterMail < 7.2.3925 - Persistent Cross-Site Scripting | smartermail | 5.0 (v2.0) | Medium |
| CVE-2011-4898 | WordPress Core 3.3.1 - Multiple Vulnerabilities | WordPress | 5.0 (v2.0) | Medium |
| CVE-2012-5451 | TVMOBiLi 2.1.0.3557 - Denial of Service | tvmobili | 5.0 (v2.0) | Medium |
| CVE-2012-5875 | FireFly Mediaserver 1.0.0.1359 - Null Pointer Dereference | firefly media server | 5.0 (v2.0) | Medium |
| CVE-2012-5876 | Nero MediaHome 4.5.8.0 - Denial of Service | mediahome | 5.0 (v2.0) | Medium |
| CVE-2012-5877 | Nero MediaHome 4.5.8.0 - Denial of Service | mediahome | 5.0 (v2.0) | Medium |
| CVE-2015-4666 | Xceedium Xsuite - Multiple Vulnerabilities | xsuite | 5.0 (v2.0) | Medium |
| CVE-2015-5531 | ElasticSearch <1.6.1 - Local File Inclusion | elasticsearch | 5.0 (v2.0) | Medium |
| CVE-2014-0865 | IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilities | algo credit limits | 4.9 (v2.0) | Medium |
| CVE-2014-0868 | IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilities | algo credit limits | 4.9 (v2.0) | Medium |
| CVE-2024-24050 | Workout Journal App 1.0 - Stored XSS | workout journal app | 4.7 (v3.1) | Medium |
| CVE-2007-3385 | Apache Tomcat 6.0.15 - Cookie Quote Handling Remote Information Disclosure | tomcat | 4.3 (v2.0) | Medium |
| CVE-2008-2938 | toutvirtual virtualiq pro 3.2 - Multiple Vulnerabilities | tomcat | 4.3 (v2.0) | Medium |
| CVE-2012-0285 | stoneware webnetwork6 - Multiple Vulnerabilities | webnetwork | 4.3 (v2.0) | Medium |
| CVE-2012-0782 | WordPress Core 3.3.1 - Multiple Vulnerabilities | WordPress | 4.3 (v2.0) | Medium |
| CVE-2013-2682 | Cisco Linksys E4200 - Multiple Vulnerabilities | linksys e4200 firmware | 4.3 (v3.1) | Medium |
| CVE-2014-0191 | eBay Magento 1.9.2.1 - PHP FPM XML eXternal Entity Injection | fusion middleware | 4.3 (v2.0) | Medium |
| CVE-2014-0866 | IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilities | algo credit limits | 4.3 (v2.0) | Medium |
| CVE-2014-0869 | IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilities | algo credit limits | 4.3 (v2.0) | Medium |
| CVE-2014-0870 | IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilities | algo credit limits | 4.3 (v2.0) | Medium |
| CVE-2014-0871 | IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilities | algo credit limits | 4.3 (v2.0) | Medium |
| CVE-2015-4665 | Xceedium Xsuite - Multiple Vulnerabilities | xsuite | 4.3 (v2.0) | Medium |
| CVE-2015-6402 | Cisco EPC 3928 - Multiple Vulnerabilities | epc3928 docsis 3.0 8x4 wireless residential gateway with embedded digital voice adapter | 4.3 (v2.0) | Medium |
| CVE-2019-13237 | Alkacon OpenCMS 10.5.x - Local File inclusion | opencms apollo template | 4.3 (v3.1) | Medium |
| CVE-2025-41228 | VMware vSphere Client 8.0.3.0 - Reflected Cross-Site Scripting (XSS) | vCenter Server | 4.3 (v3.1) | Medium |
| CVE-2014-0894 | IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilities | algo credit limits | 3.5 (v2.0) | Low |
Observed CWEs
These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.
Documentation Source
- Original wiki page: WAF 392301
- Source revision: 2376
- Source revision date: 2012-06-15