CVE-2011-1522
03.05.2011, 20:55
Multiple SQL injection vulnerabilities in the Doctrine\DBAL\Platforms\AbstractPlatform::modifyLimitQuery function in Doctrine 1.x before 1.2.4 and 2.x before 2.0.3 allow remote attackers to execute arbitrary SQL commands via the (1) limit or (2) offset field.
Vendor | Product | Version |
---|---|---|
doctrine-project | doctrine1.2.0 | * |
doctrine-project | doctrine1.2.1 | * |
doctrine-project | doctrine1.2.2 | * |
doctrine-project | doctrine1.2.3 | * |
doctrine-project | doctrine | 2.0.0 |
doctrine-project | doctrine | 2.0.0:alpha1 |
doctrine-project | doctrine | 2.0.0:alpha2 |
doctrine-project | doctrine | 2.0.0:alpha3 |
doctrine-project | doctrine | 2.0.0:alpha4 |
doctrine-project | doctrine | 2.0.0:beta1 |
doctrine-project | doctrine | 2.0.0:beta2 |
doctrine-project | doctrine | 2.0.0:beta3 |
doctrine-project | doctrine | 2.0.0:beta4 |
doctrine-project | doctrine | 2.0.0:rc1 |
doctrine-project | doctrine | 2.0.0:rc2 |
doctrine-project | doctrine | 2.0.1 |
doctrine-project | doctrine | 2.0.2 |
𝑥
= Vulnerable software versions

Debian Releases
References