SQL Injection in NukeViet's Banner Module
CVE-2019-7726
9.8CRITICAL
What is CVE-2019-7726?
The vulnerability exists in the banner module of NukeViet before version 4.3.04, where a SQL INSERT statement improperly handles raw header data from HTTP requests, including Referer and User-Agent. This could permit attackers to manipulate SQL queries and potentially extract sensitive information from the database.
