On this page
Atomicorp WAF Rule 392647
Rule Summary
- Rule ID: 392647
- Status: Active
- Alert message: Atomicorp.com WAF Rules: Multiple/Conflicting Connection Header Data Found
- Observed CWEs: CWE-20 (5), CWE-22 (10), CWE-36 (1), CWE-74 (3), CWE-77 (1), CWE-78 (5), CWE-79 (19), CWE-89 (17), CWE-91 (1), CWE-94 (4), CWE-189 (1), CWE-200 (4), CWE-255 (2), CWE-264 (2), CWE-269 (1), CWE-284 (2), CWE-287 (2), CWE-306 (2), CWE-352 (4), CWE-434 (1), CWE-502 (1), CWE-601 (1), CWE-639 (2), CWE-798 (1), CWE-862 (1), CWE-863 (2), CWE-918 (3)
- Rule severity: Alert (1)
- Phase: 1 (request headers)
- Request surfaces: Request headers
- Rule action: deny
- HTTP status: 403
- Public tags: attack-protocol
- Logging: log, auditlog
Description
This rule detects behavior identified by its current alert as “Multiple/Conflicting Connection Header Data Found” in the request headers. It evaluates during the request headers phase and denies matching traffic with HTTP status 403.
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
| CVE | Vulnerability | Product | CVSS | Severity |
|---|---|---|---|---|
| CVE-2013-5755 | Yealink VoIP Phone SIP-T38G - Remote Command Execution | sip-t38g | 10.0 (v2.0) | High |
| CVE-2014-8877 | WordPress Plugin CM Download Manager 2.0.0 - Code Injection | cm download manager | 10.0 (v2.0) | High |
| CVE-2024-46986 | Camaleon CMS < 2.8.1 Arbitrary File Write to RCE | camaleon cms | 9.9 (v3.1) | Critical |
| CVE-2013-4864 | MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities | veralite firmware | 9.8 (v3.1) | Critical |
| CVE-2014-8673 | SO Planning 1.32 - Multiple Vulnerabilities | soplanning | 9.8 (v3.1) | Critical |
| CVE-2014-9148 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | fiyo cms | 9.8 (v3.0) | Critical |
| CVE-2015-3933 | GeniXCMS 0.0.3 - 'register.php' SQL Injection | genixcms | 9.8 (v3.0) | Critical |
| CVE-2015-4664 | Xceedium Xsuite - Multiple Vulnerabilities | privileged access manager | 9.8 (v3.0) | Critical |
| CVE-2015-4667 | Xceedium Xsuite - Multiple Vulnerabilities | xsuite | 9.8 (v3.0) | Critical |
| CVE-2015-6970 | Bosch Security Systems Dinion NBN-498 - Web Interface XML Injection | nbn-498 dinion2x day/night ip cameras firmware | 9.8 (v3.1) | Critical |
| CVE-2016-4337 | Ktools Photostore 4.7.5 - Blind SQL Injection | photostore | 9.8 (v3.0) | Critical |
| CVE-2017-5689 | Intel Active Management Technology - System Privileges | proliant ml10 gen9 server firmware | 9.8 (v3.1) | Critical |
| CVE-2019-25141 | Easy WP SMTP <= 1.3.9 - Missing Authorization to Arbitrary Options Update | easy wp smtp | 9.8 (v3.1) | Critical |
| CVE-2025-59287 | Windows Server Update Service - Insecure Deserialization | Windows Server update service | 9.8 (v3.1) | Critical |
| CVE-2022-26833 | Open Automation Software OAS Platform V16.00.0121 - Missing Authentication | oas platform | 9.4 (v3.1) | Critical |
| CVE-2026-4810 | Google ADK-Python - Unauthenticated Builder Endpoint | adk-python | 9.3 (v4.0) | Critical |
| CVE-2013-5758 | Yealink VoIP Phone SIP-T38G - Privilege Escalation | sip-t38g | 9.0 (v2.0) | High |
| CVE-2014-5308 | TestLink 1.9.11 - Multiple SQL Injections | testlink | 9.0 (v2.0) | High |
| CVE-2014-7884 | ArcSight Logger - Arbitrary File Upload / Code Execution | arcsight logger | 9.0 (v2.0) | High |
| CVE-2019-7671 | Prima Access Control 2.3.35 - 'HwName' Persistent Cross-Site Scripting | flexair | 9.0 (v3.1) | Critical |
| CVE-2013-4863 | MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities | veralite firmware | 8.8 (v3.1) | High |
| CVE-2014-8356 | ZHONE < S3.0.501 - Multiple Vulnerabilities | znid 2426a firmware | 8.8 (v3.1) | High |
| CVE-2014-8357 | ZHONE < S3.0.501 - Multiple Vulnerabilities | znid 2426a firmware | 8.8 (v3.0) | High |
| CVE-2014-9118 | ZHONE < S3.0.501 - Multiple Vulnerabilities | znid 2426a firmware | 8.8 (v3.0) | High |
| CVE-2017-5799 | HPE OpenCall Media Platform (OCMP) 4.3.2 - Cross-Site Scripting / Remote File Inclusion | opencall media platform | 8.8 (v3.0) | High |
| CVE-2017-9413 | Subsonic 6.1.1 - Server-Side Request Forgery | subsonic | 8.8 (v3.0) | High |
| CVE-2019-9189 | Prima Access Control 2.3.35 - Arbitrary File Upload | flexair | 8.8 (v3.0) | High |
| CVE-2024-41667 | OpenAM<=15.0.3 FreeMarker - Template Injection | OpenAM | 8.8 (v3.1) | High |
| CVE-2024-48248 | NAKIVO Backup and Replication Solution - Unauthenticated Arbitrary File Read | backup & replication director | 8.6 (v3.1) | High |
| CVE-2013-4862 | MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities | veralite firmware | 8.1 (v3.1) | High |
| CVE-2016-1337 | Cisco EPC 3928 - Multiple Vulnerabilities | epc3928 firmware | 8.1 (v3.0) | High |
| CVE-2024-30188 | Apache DolphinScheduler >= 3.1.0, < 3.2.2 Resource File Read And Write | dolphinscheduler | 8.1 (v3.1) | High |
| CVE-2015-4669 | Xceedium Xsuite - Multiple Vulnerabilities | xsuite | 7.8 (v3.0) | High |
| CVE-2019-20499 | D-Link DWL-2600AP - Multiple OS Command Injection | dwl-2600ap firmware | 7.8 (v3.1) | High |
| CVE-2019-20500 | D-Link DWL-2600AP - Multiple OS Command Injection | dwl-2600ap firmware | 7.8 (v3.1) | High |
| CVE-2019-20501 | D-Link DWL-2600AP - Multiple OS Command Injection | dwl-2600ap firmware | 7.8 (v3.1) | High |
| CVE-2011-4448 | WikkaWiki 1.3.2 - Multiple Vulnerabilities | wikkawiki | 7.5 (v2.0) | High |
| CVE-2013-5694 | Opsview pre 4.4.1 - Blind SQL Injection | opsview | 7.5 (v2.0) | High |
| CVE-2013-6041 | Webuzo 2.1.3 - Multiple Vulnerabilities | webuzo | 7.5 (v2.0) | High |
| CVE-2014-6389 | PHPCompta/NOALYSS 6.7.1 5638 - Remote Command Execution | phpcompta/noalyss | 7.5 (v2.0) | High |
| CVE-2014-8675 | SO Planning 1.32 - Multiple Vulnerabilities | soplanning | 7.5 (v3.0) | High |
| CVE-2014-9145 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | fiyo cms | 7.5 (v2.0) | High |
| CVE-2014-9147 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | fiyo cms | 7.5 (v3.0) | High |
| CVE-2014-9215 | PBBoard CMS 3.0.1 - SQL Injection | pbboard | 7.5 (v2.0) | High |
| CVE-2014-9464 | Microweber CMS 0.95 - SQL Injection | microweber | 7.5 (v2.0) | High |
| CVE-2015-1400 | NPDS CMS REvolution-13 - SQL Injection | revolution | 7.5 (v2.0) | High |
| CVE-2015-1503 | IceWarp Mail Server < 11.1.1 - Directory Traversal | mail server | 7.5 (v3.0) | High |
| CVE-2015-1518 | RedaxScript CMS 2.2.0 - SQL Injection | redaxscript | 7.5 (v2.0) | High |
| CVE-2015-2824 | WordPress Plugin Simple Ads Manager - Multiple SQL Injections | simple ads manager | 7.5 (v2.0) | High |
| CVE-2015-6401 | Cisco EPC 3928 - Multiple Vulnerabilities | epc3928 docsis 3.0 8x4 wireless residential gateway with embedded digital voice adapter | 7.5 (v2.0) | High |
| CVE-2016-1328 | Cisco EPC 3928 - Multiple Vulnerabilities | epc3928 firmware | 7.5 (v3.0) | High |
| CVE-2016-1336 | Cisco EPC 3928 - Multiple Vulnerabilities | epc3928 firmware | 7.5 (v3.0) | High |
| CVE-2018-11222 | Pandora FMS <=7.0NG.722 - Remote Code Execution | pandora fms | 7.5 (v3.0) | High |
| CVE-2021-46381 | DLINK DAP-1620 A1 v1.01 - Directory Traversal | dap-1620 firmware | 7.5 (v3.1) | High |
| CVE-2017-9355 | Subsonic 6.1.1 - XML External Entity Injection | subsonic | 7.4 (v3.0) | High |
| CVE-2015-4027 | Acunetix WVS 10 - Local Privilege Escalation | web vulnerability scanner | 7.2 (v2.0) | High |
| CVE-2018-1002000 | WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting | arigato autoresponder and newsletter | 7.2 (v3.0) | High |
| CVE-2025-5298 | Campcodes Online Hospital Management System 1.0 - SQL Injection | online hospital management system | 6.9 (v4.0) | Medium |
| CVE-2011-4449 | WikkaWiki 1.3.2 - Multiple Vulnerabilities | wikkawiki | 6.8 (v2.0) | Medium |
| CVE-2011-4452 | WikkaWiki 1.3.2 - Multiple Vulnerabilities | wikkawiki | 6.8 (v2.0) | Medium |
| CVE-2012-0286 | stoneware webnetwork6 - Multiple Vulnerabilities | webnetwork | 6.8 (v2.0) | Medium |
| CVE-2013-4861 | MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities | veralite firmware | 6.5 (v3.1) | Medium |
| CVE-2013-4865 | MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities | veralite firmware | 6.5 (v3.1) | Medium |
| CVE-2014-7176 | Enalean Tuleap 7.4.99.5 - Blind SQL Injection | tuleap | 6.5 (v2.0) | Medium |
| CVE-2021-24405 | WordPress Plugin Easy Cookie Policy 1.6.2 - Broken Access Control to Stored XSS | easy cookies policy | 6.5 (v3.1) | Medium |
| CVE-2023-45826 | Leantime < 2.4 - Authenticated SQL Injection | leantime | 6.5 (v3.1) | Medium |
| CVE-2025-54249 | Adobe Experience Manager ≤ 6.5.23.0 – SSRF | experience manager | 6.5 (v3.1) | Medium |
| CVE-2011-4450 | WikkaWiki 1.3.2 - Multiple Vulnerabilities | wikkawiki | 6.4 (v2.0) | Medium |
| CVE-2015-4668 | Xceedium Xsuite - Multiple Vulnerabilities | xsuite | 6.1 (v3.0) | Medium |
| CVE-2017-5798 | HPE OpenCall Media Platform (OCMP) 4.3.2 - Cross-Site Scripting / Remote File Inclusion | opencall media platform | 6.1 (v3.0) | Medium |
| CVE-2014-8674 | SO Planning 1.32 - Multiple Vulnerabilities | soplanning | 5.4 (v3.1) | Medium |
| CVE-2024-48120 | X2CRM 8.5 - Stored Cross-Site Scripting (XSS) | x2crm | 5.4 (v3.1) | Medium |
| CVE-2014-8676 | SO Planning 1.32 - Multiple Vulnerabilities | soplanning | 5.3 (v3.0) | Medium |
| CVE-2014-8677 | SO Planning 1.32 - Multiple Vulnerabilities | soplanning | 5.3 (v3.0) | Medium |
| CVE-2024-53586 | WebFileSys 2.31.0 - Directory Path Traversal | - | 5.3 (v3.1) | Medium |
| CVE-2025-10493 | Chained Quiz 1.3.5 - Unauthenticated Insecure Direct Object Reference via Cookie | Chained Quiz | 5.3 (v3.1) | Medium |
| CVE-2012-5876 | Nero MediaHome 4.5.8.0 - Denial of Service | mediahome | 5.0 (v2.0) | Medium |
| CVE-2012-5877 | Nero MediaHome 4.5.8.0 - Denial of Service | mediahome | 5.0 (v2.0) | Medium |
| CVE-2013-6043 | Webuzo 2.1.3 - Multiple Vulnerabilities | webuzo | 5.0 (v2.0) | Medium |
| CVE-2015-4666 | Xceedium Xsuite - Multiple Vulnerabilities | xsuite | 5.0 (v2.0) | Medium |
| CVE-2015-4425 | Pimcore CMS Build 3450 - Directory Traversal | pimcore | 4.9 (v2.0) | Medium |
| CVE-2018-1002001 | WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting | arigato autoresponder and newsletter | 4.8 (v3.0) | Medium |
| CVE-2018-1002002 | WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting | arigato autoresponder and newsletter | 4.8 (v3.0) | Medium |
| CVE-2018-1002003 | WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting | arigato autoresponder and newsletter | 4.8 (v3.0) | Medium |
| CVE-2018-1002004 | WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting | arigato autoresponder and newsletter | 4.8 (v3.0) | Medium |
| CVE-2018-1002005 | WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting | arigato autoresponder and newsletter | 4.8 (v3.0) | Medium |
| CVE-2018-1002006 | WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting | arigato autoresponder and newsletter | 4.8 (v3.0) | Medium |
| CVE-2018-1002007 | WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting | arigato autoresponder and newsletter | 4.8 (v3.0) | Medium |
| CVE-2018-1002008 | WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting | arigato autoresponder and newsletter | 4.8 (v3.0) | Medium |
| CVE-2018-1002009 | WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting | arigato autoresponder and newsletter | 4.8 (v3.0) | Medium |
| CVE-2011-4451 | WikkaWiki 1.3.2 - Multiple Vulnerabilities | wikkawiki | 4.3 (v2.0) | Medium |
| CVE-2012-0285 | stoneware webnetwork6 - Multiple Vulnerabilities | webnetwork | 4.3 (v2.0) | Medium |
| CVE-2013-6042 | Webuzo 2.1.3 - Multiple Vulnerabilities | webuzo | 4.3 (v2.0) | Medium |
| CVE-2014-9146 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | fiyo cms | 4.3 (v2.0) | Medium |
| CVE-2015-2275 | WoltLab Community Gallery - Persistent Cross-Site Scripting | community gallery | 4.3 (v2.0) | Medium |
| CVE-2015-4665 | Xceedium Xsuite - Multiple Vulnerabilities | xsuite | 4.3 (v2.0) | Medium |
| CVE-2015-6402 | Cisco EPC 3928 - Multiple Vulnerabilities | epc3928 docsis 3.0 8x4 wireless residential gateway with embedded digital voice adapter | 4.3 (v2.0) | Medium |
| CVE-2014-1222 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | vtiger crm | 4.0 (v2.0) | Medium |
| CVE-2013-5759 | Yealink VoIP Phone SIP-T38G - Privilege Escalation | - | N/A | N/A |
Observed CWEs
These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.