HTTP: NullByte Comment Out Query SQL Injection

This signature detects attempts to perform SQL Injection. Dynamic web pages that accept user input without proper variable validation are vulnerable to arbitrary command injection.

Short Name
HTTP:SQL:INJ:NULLBYTE-COMMENT
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Comment Injection NullByte Out Query SQL
Release Date
07/11/2012
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown

Found a potential security threat?