Description
Multiple SQL injection vulnerabilities in the Doctrine\DBAL\Platforms\AbstractPlatform::modifyLimitQuery function in Doctrine 1.x before 1.2.4 and 2.x before 2.0.3 allow remote attackers to execute arbitrary SQL commands via the (1) limit or (2) offset field.
References (7)
Core 7
Core References
Mailing List mailing-list
x_refsource_mlist
http://openwall.com/lists/oss-security/2011/03/28/3
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/47034
Issue Tracking x_refsource_confirm
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=622674
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2011/dsa-2223
Patch x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=689396
Mailing List mailing-list
x_refsource_mlist
http://openwall.com/lists/oss-security/2011/03/25/2
Patch, Vendor Advisory x_refsource_confirm
http://www.doctrine-project.org/blog/doctrine-security-fix
Scores
EPSS
0.0202
EPSS Percentile
78.9%
Details
CWE
CWE-89
Status
published
Products (7)
doctrine-project/doctrine
2.0.0 (11 CPE variants)
doctrine-project/doctrine
2.0.1
doctrine-project/doctrine
2.0.2
doctrine-project/doctrine1.2.0
doctrine-project/doctrine1.2.1
doctrine-project/doctrine1.2.2
doctrine-project/doctrine1.2.3
Published
May 03, 2011
Tracked Since
Feb 18, 2026