CVE-2011-1522: SQL Injection

Published Mar 21, 2011
·
Updated

Latest upstream release: 1.2.4 Current version in Fedora Rawhide: 1.2.3 URL: http://pear.doctrine-project.org/feed.xml

Please consult the package updates policy before you issue an update to a stable branch: https://fedoraproject.org/wiki/UpdatesPolicy

More information about the service that created this bug can be found at: https://fedoraproject.org/wiki/Upstreamreleasemonitoring

Other sources

Multiple SQL injection vulnerabilities in the Doctrine\DBAL\Platforms\AbstractPlatform::modifyLimitQuery function in Doctrine 1.x before 1.2.4 and 2.x before 2.0.3 allow remote attackers to execute arbitrary SQL commands via the (1) limit or (2) offset field.

MITRE

Affected Software

17 affected components
doctrine-project Doctrine1.2.0
doctrine-project Doctrine1.2.1
doctrine-project Doctrine1.2.2
doctrine-project Doctrine1.2.3
doctrine-project doctrine=2.0.0-rc2
doctrine-project doctrine=2.0.0-alpha3
doctrine-project doctrine=2.0.0-alpha2
doctrine-project doctrine=2.0.0-beta4
doctrine-project doctrine=2.0.0-beta2
doctrine-project doctrine=2.0.0-rc1
doctrine-project doctrine=2.0.0
doctrine-project doctrine=2.0.1
doctrine-project doctrine=2.0.2
doctrine-project doctrine=2.0.0-beta1
doctrine-project doctrine=2.0.0-alpha1
doctrine-project doctrine=2.0.0-alpha4
doctrine-project doctrine=2.0.0-beta3

Event History

Mar 21, 2011
Data Sourced
via Red Hat·11:31 AM
DescriptionSeverityAffected Software
May 3, 2011
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2011-1522?

CVE-2011-1522 has a moderate severity level, which indicates it could lead to some impact but not critical issues.

2

How do I fix CVE-2011-1522?

To fix CVE-2011-1522, upgrade to version 1.2.4 or later of the Doctrine Object Relational Mapper.

3

Which versions of Doctrine are affected by CVE-2011-1522?

CVE-2011-1522 affects Doctrine versions 1.2.0 through 1.2.3 and 2.0.0 alpha, beta, and release candidate versions.

4

Is there a patch available for CVE-2011-1522?

Yes, the patch for CVE-2011-1522 is included in the updated version 1.2.4 of the Doctrine ORM.

5

What are the potential vulnerabilities of CVE-2011-1522?

The potential vulnerabilities of CVE-2011-1522 could lead to application integrity issues or data leakage under certain circumstances.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203