CVE-2011-1522

Doctrine <1.2.4, <2.0.3 - SQL Injection

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in the Doctrine\DBAL\Platforms\AbstractPlatform::modifyLimitQuery function in Doctrine 1.x before 1.2.4 and 2.x before 2.0.3 allow remote attackers to execute arbitrary SQL commands via the (1) limit or (2) offset field.

References (7)

Core 7
Core References
Mailing List mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2011/03/28/3
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/47034
Issue Tracking x_refsource_confirm
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=622674
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2011/dsa-2223
Mailing List mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2011/03/25/2
Patch, Vendor Advisory x_refsource_confirm
http://www.doctrine-project.org/blog/doctrine-security-fix

Scores

EPSS 0.0202
EPSS Percentile 78.9%

Details

CWE
CWE-89
Status published
Products (7)
doctrine-project/doctrine 2.0.0 (11 CPE variants)
doctrine-project/doctrine 2.0.1
doctrine-project/doctrine 2.0.2
doctrine-project/doctrine1.2.0
doctrine-project/doctrine1.2.1
doctrine-project/doctrine1.2.2
doctrine-project/doctrine1.2.3
Published May 03, 2011
Tracked Since Feb 18, 2026