VYPR

ARC2

by Arc

Source repositories

CVEs (2)

  • CVE-2012-5872CriApr 26, 2023
    risk 0.57cvss 9.8epss 0.01

    ARC (aka ARC2) through 2011-12-01 allows blind SQL Injection in getTriplePatternSQL in ARC2_StoreSelectQueryHandler.php via comments in a SPARQL WHERE clause.

  • CVE-2012-5873MedApr 26, 2023
    risk 0.27cvss 5.3epss 0.00

    ARC (aka ARC2) through 2011-12-01 allows reflected XSS via the end_point.php query parameter in an output=htmltab action.