Secunia Advisory:
http://secunia.com/advisories/20176/
Don't worry about it if you've installed Protector.
It is just a well-known attack, and Protector shuts out and logs it.
(Both Null-byte and Injection will be reported if such an attack comes)
If you don't/won't install Protector, check register_global is disabled, again.
(Though I can't imagine public XOOPS sites without Protector )
You should know the worst vulnerability is not SA20176 itself but the setting of register_globals=on.