http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-2865 "Cross-site scripting (XSS) vulnerability in sqledit.php in phpPgAdmin 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the server parameter."
Upstream fixed this; packages will be updated shortly.
This is already done, forgot to close the ticket.