Doctrine Project Database Abstraction Layer Library 'modifyLimitQuery()' SQL Injection Vulnerability
BID:47034
Info
Doctrine Project Database Abstraction Layer Library 'modifyLimitQuery()' SQL Injection Vulnerability
| Bugtraq ID: | 47034 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-1522 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 20 2011 12:00AM |
| Updated: | Apr 13 2015 09:33PM |
| Credit: | The vendor has reported this issue. |
| Vulnerable: |
Doctrine Project Doctrine 2.0.2 Doctrine Project Doctrine 1.2.3 Doctrine Project Doctrine 1.2.2 Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 |
| Not Vulnerable: |
Doctrine Project Doctrine 2.0.3 Doctrine Project Doctrine 1.2.4 |
Discussion
Doctrine Project Database Abstraction Layer Library 'modifyLimitQuery()' SQL Injection Vulnerability
The Doctrine Project Database Abstraction Layer library is prone to an SQL-injection vulnerability because it fails to properly sanitize user-supplied input.
Exploiting this issue can allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to Doctrine 1.2.4 and 2.0.3 are vulnerable.
The Doctrine Project Database Abstraction Layer library is prone to an SQL-injection vulnerability because it fails to properly sanitize user-supplied input.
Exploiting this issue can allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to Doctrine 1.2.4 and 2.0.3 are vulnerable.
Exploit / POC
Doctrine Project Database Abstraction Layer Library 'modifyLimitQuery()' SQL Injection Vulnerability
Attackers can exploit this issue through a browser.
Attackers can exploit this issue through a browser.
Solution / Fix
Doctrine Project Database Abstraction Layer Library 'modifyLimitQuery()' SQL Injection Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Doctrine Project Database Abstraction Layer Library 'modifyLimitQuery()' SQL Injection Vulnerability
References:
References:
- Doctrine Project Homepage (Doctrine Project)
- Security Fix: Upgrade to 1.2.4 and 2.0.3 immediately (Doctrine Project)