CVE-2011-1522

Multiple SQL injection vulnerabilities in the Doctrine\DBAL\Platforms\AbstractPlatform::modifyLimitQuery function in Doctrine 1.x before 1.2.4 and 2.x before 2.0.3 allow remote attackers to execute arbitrary SQL commands via the (1) limit or (2) offset field.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:doctrine-project:doctrine1.2.0:*:*:*:*:*:*:*:*
cpe:2.3:a:doctrine-project:doctrine1.2.1:*:*:*:*:*:*:*:*
cpe:2.3:a:doctrine-project:doctrine1.2.2:*:*:*:*:*:*:*:*
cpe:2.3:a:doctrine-project:doctrine1.2.3:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:doctrine-project:doctrine:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:doctrine-project:doctrine:2.0.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:doctrine-project:doctrine:2.0.0:alpha2:*:*:*:*:*:*
cpe:2.3:a:doctrine-project:doctrine:2.0.0:alpha3:*:*:*:*:*:*
cpe:2.3:a:doctrine-project:doctrine:2.0.0:alpha4:*:*:*:*:*:*
cpe:2.3:a:doctrine-project:doctrine:2.0.0:beta1:*:*:*:*:*:*
cpe:2.3:a:doctrine-project:doctrine:2.0.0:beta2:*:*:*:*:*:*
cpe:2.3:a:doctrine-project:doctrine:2.0.0:beta3:*:*:*:*:*:*
cpe:2.3:a:doctrine-project:doctrine:2.0.0:beta4:*:*:*:*:*:*
cpe:2.3:a:doctrine-project:doctrine:2.0.0:rc1:*:*:*:*:*:*
cpe:2.3:a:doctrine-project:doctrine:2.0.0:rc2:*:*:*:*:*:*
cpe:2.3:a:doctrine-project:doctrine:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:doctrine-project:doctrine:2.0.2:*:*:*:*:*:*:*

History

21 Nov 2024, 01:26

Type Values Removed Values Added
References () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=622674 - () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=622674 -
References () http://openwall.com/lists/oss-security/2011/03/25/2 - () http://openwall.com/lists/oss-security/2011/03/25/2 -
References () http://openwall.com/lists/oss-security/2011/03/28/3 - () http://openwall.com/lists/oss-security/2011/03/28/3 -
References () http://www.debian.org/security/2011/dsa-2223 - () http://www.debian.org/security/2011/dsa-2223 -
References () http://www.doctrine-project.org/blog/doctrine-security-fix - Patch, Vendor Advisory () http://www.doctrine-project.org/blog/doctrine-security-fix - Patch, Vendor Advisory
References () http://www.securityfocus.com/bid/47034 - () http://www.securityfocus.com/bid/47034 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=689396 - Patch () https://bugzilla.redhat.com/show_bug.cgi?id=689396 - Patch

Information

Published : 2011-05-03 20:55

Updated : 2024-11-21 01:26


NVD link : CVE-2011-1522

Mitre link : CVE-2011-1522

CVE.ORG link : CVE-2011-1522


JSON object : View

Products Affected

doctrine-project

  • doctrine1.2.1
  • doctrine1.2.0
  • doctrine
  • doctrine1.2.2
  • doctrine1.2.3
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')