From the upstream advisory: http://www.phpmyadmin.net/home_page/security/PMASA-2011-13.php Announcement-ID: PMASA-2011-13 Date: 2011-08-24 Summary: Multiple XSS in the Tracking feature. Description: Missing sanitization on the table, column and index names leads to XSS vulnerabilities. Severity We consider this vulnerability to be serious. Mitigation factor: An attacker must be logged in via phpMyAdmin to exploit this problem. Affected Versions Versions 3.3.0 to 3.4.3.2 are affected. Solution: Upgrade to phpMyAdmin 3.3.10.4 or 3.4.4 or apply the related patch listed below. References This issue was found by Norman Hippert from The-Wildcat.de. Assigned CVE ids: CVE-2011-3181 CWE ids: CWE-661 CWE-98
Created phpMyAdmin tracking bugs for this issue Affects: fedora-all [bug 733477] Affects: epel-4 [bug 733478] Affects: epel-5 [bug 733479] Affects: epel-6 [bug 733480]
Josh, you did a lookup mistake, I think. EPEL 4 and 5 are *not* affected, because they ship phpMyAdmin 2.x, just EPEL 6 and all Fedora releases.