7.5
CVSSv2

CVE-2011-1522

Published: 03/05/2011 Updated: 31/05/2011
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in the Doctrine\DBAL\Platforms\AbstractPlatform::modifyLimitQuery function in Doctrine 1.x prior to 1.2.4 and 2.x prior to 2.0.3 allow remote malicious users to execute arbitrary SQL commands via the (1) limit or (2) offset field.

Vulnerable Product Search on Vulmon Subscribe to Product

doctrine-project doctrine1.2.1

doctrine-project doctrine1.2.3

doctrine-project doctrine1.2.0

doctrine-project doctrine1.2.2

doctrine-project doctrine 2.0.0

doctrine-project doctrine 2.0.1

doctrine-project doctrine 2.0.2

Vendor Advisories

Debian Bug report logs - #622674 CVE-2011-1522: SQL injection Package: doctrine; Maintainer for doctrine is Debian PHP PEAR Maintainers <pkg-php-pear@listsaliothdebianorg>; Source for doctrine is src:doctrine (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Wed, 13 Apr 2011 18:48:04 UTC ...
It was discovered that Doctrine, a PHP library for implementing object persistence, contains SQL injection vulnerabilities The exact impact depends on the application which uses the Doctrine library For the stable distribution (squeeze), this problem has been fixed in version 122-2+squeeze1 We recommend that you upgrade your doctrine packages ...