On this page
Atomicorp WAF Rule 390613
Rule Summary
- Rule ID: 390613
- Status: Active
- Alert message: Atomicorp.com WAF Rules: Null Byte Attack Blocked (Invalid character in request or headers)
- Observed CWEs: CWE-20 (2), CWE-22 (118), CWE-73 (1), CWE-77 (1), CWE-89 (2), CWE-94 (2), CWE-200 (1), CWE-306 (1), CWE-502 (5), CWE-862 (1)
- Revision: 10
- Rule severity: Critical (2)
- Phase: 2 (request body)
- Request surfaces: Request URI, Request headers, Request arguments, JSON request data, SOAP request data
- Rule action: deny
- HTTP status: 403
- Logging: log, auditlog
Description
This rules detects NULL characters in the request URL or in a header for the request. NULL characters are often used by attackers to try an bypass intrusion detection systems, as there have been vulnerabilities in IDS’ (including modsecurity) that have allowed attackers to bypass IDS systems. The Rules will detect the use of NULL characters and will block them.
Example attack'
GET /index.php?option=com_shoutbox&controller=../../../../../../../../../../../../../../../proc/self/environ%00 HTTP/1.1
The last character in this request is a null, which is invalid and is part of an actual attack on the system. The above example is an attacker attempting to access the Linux /proc file system via a recursion attack, with an added NULL character at the end to attempt to evade the IDS system.
Similar Rules
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
| CVE | Vulnerability | Product | CVSS | Severity |
|---|---|---|---|---|
| CVE-2010-5286 | Joomla! Component Jstore - 'Controller' Local File Inclusion | com jstore | 10.0 (v2.0) | High |
| CVE-2026-34838 | Group-Office: Authenticated Remote Code Execution via PHP Insecure Deserialization in AbstractSettingsCollection | group-office | 9.9 (v3.1) | Critical |
| CVE-2010-2861 | Adobe ColdFusion - Directory Traversal | coldfusion | 9.8 (v3.1) | Critical |
| CVE-2014-6287 | HTTP File Server <2.3c - Remote Command Execution | http file server | 9.8 (v3.1) | Critical |
| CVE-2020-29227 | Car Rental Management System 1.0 - Local File Inclusion | car rental management system | 9.8 (v3.1) | Critical |
| CVE-2021-45467 | Control Web Panel (CWP) - File Inclusion | webpanel | 9.8 (v3.1) | Critical |
| CVE-2022-1391 | WordPress Cab fare calculator < 1.0.4 - Local File Inclusion | cab fare calculator | 9.8 (v3.1) | Critical |
| CVE-2023-23333 | SolarView Compact 6.00 - OS Command Injection | solarview compact firmware | 9.8 (v3.1) | Critical |
| CVE-2026-19912 | Kaltura HTML5 Video Player, html5 library Arbitrary Code Execution Vulnerability | Kaltura HTML5 Video Player, html5 library | 9.8 (v3.1) | Critical |
| CVE-2026-10042 | manga-image-translator RCE via Unsafe Pickle Deserialization in Share Model | manga-image-translator | 9.2 (v4.0) | Critical |
| CVE-2026-87930 | MaxSite CMS through 109.6 PHP Object Injection via ci_session | MaxSite CMS | 9.2 (v4.0) | Critical |
| CVE-2026-14602 | Remote API <= 0.2 - Unauthenticated PHP Object Injection via remote-api Query Parameter | Remote API | 9.0 (v3.1) | Critical |
| CVE-2020-8641 | Lotus Core CMS 1.0.1 - Local File Inclusion | lotus core cms | 8.8 (v3.1) | High |
| CVE-2025-71260 | BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 VIEWSTATE Deserialization RCE | footprints | 8.7 (v4.0) | High |
| CVE-2026-71981 | Cypht < 2.12.2 PHP Object Injection RCE via back_query Parameter | cypht | 8.7 (v4.0) | High |
| CVE-2006-2842 | Squirrelmail <=1.4.6 - Local File Inclusion | squirrelmail | 7.5 (v2.0) | High |
| CVE-2010-0972 | Joomla! Component com_gcalendar Suite 2.1.5 - Local File Inclusion | com gcalendar | 7.5 (v2.0) | High |
| CVE-2010-0985 | Joomla! Component com_abbrev - Local File Inclusion | com abbrev | 7.5 (v2.0) | High |
| CVE-2010-1306 | Joomla! Component Picasa 2.0 - Local File Inclusion | com joomlapicasa2 | 7.5 (v2.0) | High |
| CVE-2010-1470 | Joomla! Component Web TV 1.0 - Local File Inclusion | com webtv | 7.5 (v2.0) | High |
| CVE-2010-1471 | Joomla! Component Address Book 1.5.0 - Local File Inclusion | com addressbook | 7.5 (v2.0) | High |
| CVE-2010-1472 | Joomla! Component Horoscope 1.5.0 - Local File Inclusion | com horoscope | 7.5 (v2.0) | High |
| CVE-2010-1495 | Joomla! Component Matamko 1.01 - Local File Inclusion | com matamko | 7.5 (v2.0) | High |
| CVE-2010-1531 | Joomla! Component redSHOP 1.0 - Local File Inclusion | com redshop | 7.5 (v2.0) | High |
| CVE-2010-1533 | Joomla! Component TweetLA 1.0.1 - Local File Inclusion | com tweetla | 7.5 (v2.0) | High |
| CVE-2010-1535 | Joomla! Component TRAVELbook 1.0.1 - Local File Inclusion | com travelbook | 7.5 (v2.0) | High |
| CVE-2010-1602 | Joomla! Component ZiMB Comment 0.8.1 - Local File Inclusion | com zimbcomment | 7.5 (v2.0) | High |
| CVE-2010-1603 | Joomla! Component ZiMBCore 0.1 - Local File Inclusion | com zimbcore | 7.5 (v2.0) | High |
| CVE-2010-1653 | Joomla! Component Graphics 1.0.6 - Local File Inclusion | com graphics | 7.5 (v2.0) | High |
| CVE-2010-1717 | Joomla! Component iF surfALERT 1.2 - Local File Inclusion | if surfalert | 7.5 (v2.0) | High |
| CVE-2010-1875 | Joomla! Component Property - Local File Inclusion | com properties | 7.5 (v2.0) | High |
| CVE-2010-1878 | Joomla! Component OrgChart 1.0.0 - Local File Inclusion | com orgchart | 7.5 (v2.0) | High |
| CVE-2010-1952 | Joomla! Component BeeHeard 1.0 - Local File Inclusion | com beeheard | 7.5 (v2.0) | High |
| CVE-2010-1953 | Joomla! Component iNetLanka Multiple Map 1.0 - Local File Inclusion | com multimap | 7.5 (v2.0) | High |
| CVE-2010-1954 | Joomla! Component iNetLanka Multiple root 1.0 - Local File Inclusion | com multiroot | 7.5 (v2.0) | High |
| CVE-2010-1955 | Joomla! Component Deluxe Blog Factory 1.1.2 - Local File Inclusion | com blogfactory | 7.5 (v2.0) | High |
| CVE-2010-1956 | Joomla! Component Gadget Factory 1.0.0 - Local File Inclusion | com gadgetfactory | 7.5 (v2.0) | High |
| CVE-2010-1957 | Joomla! Component Love Factory 1.3.4 - Local File Inclusion | com lovefactory | 7.5 (v2.0) | High |
| CVE-2010-1977 | Joomla! Component J!WHMCS Integrator 1.5.0 - Local File Inclusion | com jwhmcs | 7.5 (v2.0) | High |
| CVE-2010-1980 | Joomla! Component Joomla! Flickr 1.0 - Local File Inclusion | com joomlaflickr | 7.5 (v2.0) | High |
| CVE-2010-1983 | Joomla! Component redTWITTER 1.0 - Local File Inclusion | com redtwitter | 7.5 (v2.0) | High |
| CVE-2010-2033 | Joomla! Percha Categories Tree 0.6 - Local File Inclusion | com perchacategoriestree | 7.5 (v2.0) | High |
| CVE-2010-2034 | Joomla! Component Percha Image Attach 1.1 - Directory Traversal | com perchaimageattach | 7.5 (v2.0) | High |
| CVE-2010-2035 | Joomla! Component Percha Gallery 1.6 Beta - Directory Traversal | com perchagallery | 7.5 (v2.0) | High |
| CVE-2010-2036 | Joomla! Component Percha Fields Attach 1.0 - Directory Traversal | com perchafieldsattach | 7.5 (v2.0) | High |
| CVE-2010-2037 | Joomla! Component Percha Downloads Attach 1.1 - Directory Traversal | com perchadownloadsattach | 7.5 (v2.0) | High |
| CVE-2010-2045 | Joomla! Component FDione Form Wizard 1.0.2 - Local File Inclusion | com dioneformwizard | 7.5 (v2.0) | High |
| CVE-2010-2050 | Joomla! Component MS Comment 0.8.0b - Local File Inclusion | com mscomment | 7.5 (v2.0) | High |
| CVE-2010-2128 | Joomla! Component JE Quotation Form 1.0b1 - Local File Inclusion | com jequoteform | 7.5 (v2.0) | High |
| CVE-2010-2259 | Joomla! Component com_bfsurvey - Local File Inclusion | com bfsurvey profree | 7.5 (v2.0) | High |
| CVE-2010-2682 | Joomla! Component Realtyna Translator 1.0.15 - Local File Inclusion | com realtyna | 7.5 (v2.0) | High |
| CVE-2010-3426 | Joomla! Component Jphone 1.0 Alpha 3 - Local File Inclusion | com jphone | 7.5 (v2.0) | High |
| CVE-2010-4719 | Joomla! Component JRadio - Local File Inclusion | com jradio | 7.5 (v2.0) | High |
| CVE-2010-4769 | Joomla! Component Jimtawl 1.0.2 - Local File Inclusion | com jimtawl | 7.5 (v2.0) | High |
| CVE-2010-4977 | Joomla! Component Canteen 1.0 - Local File Inclusion | com canteen | 7.5 (v2.0) | High |
| CVE-2010-5028 | Joomla! Component JE Job 1.0 - Local File Inclusion | com jejob | 7.5 (v2.0) | High |
| CVE-2014-10037 | DomPHP 0.83 - Directory Traversal | domphp | 7.5 (v2.0) | High |
| CVE-2017-9833 | BOA Web Server 0.94.14 - Arbitrary File Access | boa | 7.5 (v3.1) | High |
| CVE-2018-15138 | LG-Ericsson iPECS NMS 30M - Local File Inclusion | ipecs nms | 7.5 (v3.0) | High |
| CVE-2019-7254 | eMerge E3 1.00-06 - Local File Inclusion | linear emerge essential firmware | 7.5 (v3.1) | High |
| CVE-2020-35598 | Advanced Comment System 1.0 - Local File Inclusion | advanced comment system | 7.5 (v3.1) | High |
| CVE-2022-29298 | SolarView Compact 6.00 - Local File Inclusion | sv-cpt-mc310 firmware | 7.5 (v3.1) | High |
| CVE-2023-40924 | SolarView Compact < 6.00 - Directory Traversal | solarview compact firmware | 7.5 (v3.1) | High |
| CVE-2026-19913 | Kaltura HTML5 Video Player, html5lib library Improper Input Validation Vulnerability | Kaltura HTML5 Video Player, html5lib library | 7.5 (v3.1) | High |
| CVE-2025-71257 | BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication Bypass | footprints itsm | 6.9 (v4.0) | Medium |
| CVE-2008-2650 | CMSimple 3.1 - Local File Inclusion | cmsimple | 6.8 (v2.0) | Medium |
| CVE-2008-6172 | Joomla! Component RWCards 3.0.11 - Local File Inclusion | rwcards | 6.8 (v2.0) | Medium |
| CVE-2010-1056 | Joomla! Component com_rokdownloads - Local File Inclusion | com rokdownloads | 6.8 (v2.0) | Medium |
| CVE-2010-1219 | Joomla! Component com_janews - Local File Inclusion | com janews | 6.8 (v2.0) | Medium |
| CVE-2010-1469 | Joomla! Component JProject Manager 1.0 - Local File Inclusion | com jprojectmanager | 6.8 (v2.0) | Medium |
| CVE-2010-1473 | Joomla! Component Advertising 0.25 - Local File Inclusion | com advertising | 6.8 (v2.0) | Medium |
| CVE-2010-1474 | Joomla! Component Sweetykeeper 1.5 - Local File Inclusion | com sweetykeeper | 6.8 (v2.0) | Medium |
| CVE-2010-1475 | Joomla! Component Preventive And Reservation 1.0.5 - Local File Inclusion | com preventive | 6.8 (v2.0) | Medium |
| CVE-2010-1476 | Joomla! Component AlphaUserPoints 1.5.5 - Local File Inclusion | com alphauserpoints | 6.8 (v2.0) | Medium |
| CVE-2010-1478 | Joomla! Component Jfeedback 1.2 - Local File Inclusion | com jfeedback | 6.8 (v2.0) | Medium |
| CVE-2010-1607 | Joomla! Component WMI 1.5.0 - Local File Inclusion | com wmi | 6.8 (v2.0) | Medium |
| CVE-2010-1715 | Joomla! Component Online Exam 1.5.0 - Local File Inclusion | com onlineexam | 6.8 (v2.0) | Medium |
| CVE-2010-1718 | Joomla! Component Archery Scores 1.0.6 - Local File Inclusion | com archeryscores | 6.8 (v2.0) | Medium |
| CVE-2010-1719 | Joomla! Component MT Fire Eagle 1.2 - Local File Inclusion | com mtfireeagle | 6.8 (v2.0) | Medium |
| CVE-2010-1722 | Joomla! Component Online Market 2.x - Local File Inclusion | com market | 6.8 (v2.0) | Medium |
| CVE-2010-1723 | Joomla! Component iNetLanka Contact Us Draw Root Map 1.1 - Local File Inclusion | com drawroot | 6.8 (v2.0) | Medium |
| CVE-2010-1979 | Joomla! Component Affiliate Datafeeds 880 - Local File Inclusion | com datafeeds | 6.8 (v2.0) | Medium |
| CVE-2010-1981 | Joomla! Component Fabrik 2.0 - Local File Inclusion | fabrik | 6.8 (v2.0) | Medium |
| CVE-2010-2122 | Joomla! Component simpledownload <=0.9.5 - Arbitrary File Retrieval | com simpledownload | 6.8 (v2.0) | Medium |
| CVE-2010-2507 | Joomla! Component Picasa2Gallery 1.2.8 - Local File Inclusion | com picasa2gallery | 6.8 (v2.0) | Medium |
| CVE-2010-2857 | Joomla! Component Music Manager - Local File Inclusion | com music | 6.8 (v2.0) | Medium |
| CVE-2010-2920 | Joomla! Component Foobla Suggestions 1.5.1.2 - Local File Inclusion | com foobla suggestions | 6.8 (v2.0) | Medium |
| CVE-2010-4617 | Joomla! Component JotLoader 2.2.1 - Local File Inclusion | com jotloader | 6.8 (v2.0) | Medium |
| CVE-2011-2744 | Chyrp 2.x - Local File Inclusion | chyrp | 6.8 (v2.0) | Medium |
| CVE-2016-6435 | Cisco Firepower Threat Management Console 6.0.1 - Local File Inclusion | secure firewall management center | 6.5 (v3.0) | Medium |
| CVE-2017-14537 | Trixbox 2.8.0 - Path Traversal | trixbox | 6.5 (v3.1) | Medium |
| CVE-2009-0932 | Horde/Horde Groupware - Local File Inclusion | horde | 6.4 (v2.0) | Medium |
| CVE-2010-0467 | Joomla! Component CCNewsLetter - Local File Inclusion | com ccnewsletter | 5.8 (v3.1) | Medium |
| CVE-2010-0942 | Joomla! Component com_jvideodirect - Directory Traversal | com jvideodirect | 5.0 (v2.0) | Medium |
| CVE-2010-0943 | Joomla! Component com_jashowcase - Directory Traversal | com jashowcase | 5.0 (v2.0) | Medium |
| CVE-2010-0944 | Joomla! Component com_jcollection - Directory Traversal | com jcollection | 5.0 (v2.0) | Medium |
| CVE-2010-1081 | Joomla! Component com_communitypolls 1.5.2 - Local File Inclusion | com communitypolls | 5.0 (v2.0) | Medium |
| CVE-2010-1302 | Joomla! Component DW Graph - Local File Inclusion | com dwgraphs | 5.0 (v2.0) | Medium |
| CVE-2010-1304 | Joomla! Component User Status - Local File Inclusion | com userstatus | 5.0 (v2.0) | Medium |
| CVE-2010-1305 | Joomla! Component JInventory 1.23.02 - Local File Inclusion | com jinventory | 5.0 (v2.0) | Medium |
| CVE-2010-1307 | Joomla! Component Magic Updater - Local File Inclusion | com joomlaupdater | 5.0 (v2.0) | Medium |
| CVE-2010-1308 | Joomla! Component SVMap 1.1.1 - Local File Inclusion | com svmap | 5.0 (v2.0) | Medium |
| CVE-2010-1312 | Joomla! Component News Portal 1.5.x - Local File Inclusion | com news portal | 5.0 (v2.0) | Medium |
| CVE-2010-1314 | Joomla! Component Highslide 1.5 - Local File Inclusion | com hsconfig | 5.0 (v2.0) | Medium |
| CVE-2010-1315 | Joomla! Component webERPcustomer - Local File Inclusion | com weberpcustomer | 5.0 (v2.0) | Medium |
| CVE-2010-1340 | Joomla! Component com_jresearch - 'Controller' Local File Inclusion | com jresearch | 5.0 (v2.0) | Medium |
| CVE-2010-1345 | Joomla! Component Cookex Agency CKForms - Local File Inclusion | com ckforms | 5.0 (v2.0) | Medium |
| CVE-2010-1352 | Joomla! Component Juke Box 1.7 - Local File Inclusion | com jukebox | 5.0 (v2.0) | Medium |
| CVE-2010-1353 | Joomla! Component LoginBox - Local File Inclusion | com loginbox | 5.0 (v2.0) | Medium |
| CVE-2010-1354 | Joomla! Component VJDEO 1.0 - Local File Inclusion | com vjdeo | 5.0 (v2.0) | Medium |
| CVE-2010-1461 | Joomla! Component Photo Battle 1.0.1 - Local File Inclusion | com photobattle | 5.0 (v2.0) | Medium |
| CVE-2010-1491 | Joomla! Component MMS Blog 2.3.0 - Local File Inclusion | com mmsblog | 5.0 (v2.0) | Medium |
| CVE-2010-1494 | Joomla! Component AWDwall 1.5.4 - Local File Inclusion | com awdwall | 5.0 (v2.0) | Medium |
| CVE-2010-1532 | Joomla! Component PowerMail Pro 1.5.3 - Local File Inclusion | com powermail | 5.0 (v2.0) | Medium |
| CVE-2010-1534 | Joomla! Component Shoutbox Pro - Local File Inclusion | com shoutbox | 5.0 (v2.0) | Medium |
| CVE-2010-1540 | Joomla! Component com_blog - Directory Traversal | com myblog | 5.0 (v2.0) | Medium |
| CVE-2010-1601 | Joomla! Component JA Comment - Local File Inclusion | com jacomment | 5.0 (v2.0) | Medium |
| CVE-2010-1657 | Joomla! Component SmartSite 1.0.0 - Local File Inclusion | com smartsite | 5.0 (v2.0) | Medium |
| CVE-2010-1658 | Joomla! Component NoticeBoard 1.3 - Local File Inclusion | com noticeboard | 5.0 (v2.0) | Medium |
| CVE-2010-1659 | Joomla! Component Ultimate Portfolio 1.0 - Local File Inclusion | com ultimateportfolio | 5.0 (v2.0) | Medium |
| CVE-2010-1714 | Joomla! Component Arcade Games 1.0 - Local File Inclusion | com arcadegames | 5.0 (v2.0) | Medium |
| CVE-2010-1858 | Joomla! Component SMEStorage - Local File Inclusion | com smestorage | 5.0 (v2.0) | Medium |
| CVE-2010-1982 | Joomla! Component JA Voice 2.0 - Local File Inclusion | com javoice | 5.0 (v2.0) | Medium |
| CVE-2011-4804 | Joomla! Component com_kp - 'Controller' Local File Inclusion | com obsuggest | 5.0 (v2.0) | Medium |
| CVE-2012-0996 | 11in1 CMS 1.2.1 - Local File Inclusion (LFI) | 11in1 | 5.0 (v2.0) | Medium |
| CVE-2013-5979 | Xibo 1.2.2/1.4.1 - Directory Traversal | xibo | 5.0 (v2.0) | Medium |
| CVE-2013-7091 | Zimbra Collaboration Server 7.2.2/8.0.2 Local File Inclusion | zimbra collaboration suite | 5.0 (v2.0) | Medium |
| CVE-2014-5111 | Fonality trixbox - Local File Inclusion | trixbox | 5.0 (v2.0) | Medium |
| CVE-2008-5587 | phpPgAdmin <=4.2.1 - Local File Inclusion | phppgadmin | 4.3 (v2.0) | Medium |
| CVE-2010-1217 | Joomla! Component & Plugin JE Tooltip 1.0 - Local File Inclusion | je form creator | 4.3 (v2.0) | Medium |
| CVE-2010-1313 | Joomla! Component Saber Cart 1.0.0.12 - Local File Inclusion | com sebercart | 4.3 (v2.0) | Medium |
| CVE-2010-5278 | MODx manager - Local File Inclusion | modx revolution | 4.3 (v2.0) | Medium |
| CVE-2012-4253 | MySQLDumper 1.24.4 - Directory Traversal | mysqldumper | 4.3 (v2.0) | Medium |
| CVE-2012-0991 | OpenEMR 4.1 - Local File Inclusion | openemr | 3.5 (v2.0) | Low |
Observed CWEs
These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.
Documentation Source
- Original wiki page: WAF 390613
- Source revision: 1094
- Source revision date: 2010-11-18