Announcement-ID: PMASA-2008-9
Date: 2008-10-30
XSS on a Designer component
A logged-in user can be subject of cross site scripting attack via the pmd_pdf.php script.
We consider this vulnerability to be serious.
For 2.11.x: versions before 2.11.9.3.
For 3.0.x: versions before 3.0.1.1.
Upgrade to phpMyAdmin 2.11.9.3 or 3.0.1.1.
Advisory: http://www.securityfocus.com/bid/31928/info
Assigned CVE ids: CVE-2008-4775
The following commits have been made to fix this issue:
The following commits have been made on the 2.11 branch to fix this issue:
For further information and in case of questions, please contact the phpMyAdmin team. Our website is phpmyadmin.net.