It was reported [1] that phpMyAdmin 3.4.x suffered from an XSS in replication setup, that could allow a malicious user to conduct an XSS attack using a crafted database name. All 3.4.x versions are affected, and this is fixed in upstream 3.4.10.1 [2]. [1] http://www.phpmyadmin.net/home_page/security/PMASA-2012-1.php [2] https://github.com/phpmyadmin/phpmyadmin/commit/86073d532aed656550cb731aa5b4288b126ae7a6
Created phpMyAdmin tracking bugs for this issue Affects: fedora-all [bug 795021] Affects: epel-6 [bug 795022]
Created phpMyAdmin3 tracking bugs for this issue Affects: epel-5 [bug 795023]
phpMyAdmin-3.5.0-1.el6 has been pushed to the Fedora EPEL 6 stable repository. If problems still persist, please make note of it in this bug report.
phpMyAdmin3-3.5.0-1.el5 has been pushed to the Fedora EPEL 5 stable repository. If problems still persist, please make note of it in this bug report.
phpMyAdmin-3.5.0-1.fc15 has been pushed to the Fedora 15 stable repository. If problems still persist, please make note of it in this bug report.
phpMyAdmin-3.5.0-1.fc16 has been pushed to the Fedora 16 stable repository. If problems still persist, please make note of it in this bug report.
phpMyAdmin-3.5.0-1.fc17 has been pushed to the Fedora 17 stable repository. If problems still persist, please make note of it in this bug report.