Security Advisory

CVE-2012-5872

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-04-25 00:00:00
Last updated 2025-02-03 21:05:45
Assigner mitre
CVSS score 9.8
State PUBLISHED

Description

ARC (aka ARC2) through 2011-12-01 allows blind SQL Injection in getTriplePatternSQL in ARC2_StoreSelectQueryHandler.php via comments in a SPARQL WHERE clause.