On this page

Atomicorp WAF Rule 390552

Rule Summary

  • Rule ID: 390552
  • Status: Retired
  • Alert message: Atomicorp.com WAF Rules - Virtual Just In Time Patch: Possible SQL injection in password or username field, disable this rule if you know your application is not vulnerable to this.
  • Observed CWEs: None documented

Description

This rules detects access the use of certain metacharacters that are used in SQL injection attacks for the username and password variables.

If you know your web application is not vulnerable to SQL injection attacks in the username and password variables, disable this rule.

Troubleshooting

False Positives

None.

Tuning Guidance

Please see the Tuning the Atomicorp WAF Rules page for basic information.

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

No selected related public CVE research notes are currently published.

Documentation Source

  • Original wiki page: WAF 390552
  • Source revision: 2888
  • Source revision date: 2012-11-23