The 4.0.10.4, 4.1.14.5, and 4.2.9.1 releases of phpMyAdmin fix a cross-site scripting (XSS) flaw: "With a crafted ENUM value it is possible to trigger an XSS in table search and table structure pages." The attacker must have a valid login. References: http://www.phpmyadmin.net/home_page/security/PMASA-2014-11.php
Created phpMyAdmin tracking bugs for this issue: Affects: fedora-all [bug 1148665] Affects: epel-5 [bug 1148666] Affects: epel-6 [bug 1148668] Affects: epel-7 [bug 1148669]
Created phpMyAdmin3 tracking bugs for this issue: Affects: epel-5 [bug 1148667]
phpMyAdmin-4.2.9.1-1.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report.
phpMyAdmin-4.0.10.4-1.el6 has been pushed to the Fedora EPEL 6 stable repository. If problems still persist, please make note of it in this bug report.
phpMyAdmin-4.2.9.1-1.fc21 has been pushed to the Fedora 21 stable repository. If problems still persist, please make note of it in this bug report.
phpMyAdmin-4.2.9.1-1.fc19 has been pushed to the Fedora 19 stable repository. If problems still persist, please make note of it in this bug report.
phpMyAdmin-4.2.9.1-1.el7 has been pushed to the Fedora EPEL 7 stable repository. If problems still persist, please make note of it in this bug report.
phpMyAdmin4-4.0.10.4-1.el5 has been pushed to the Fedora EPEL 5 stable repository. If problems still persist, please make note of it in this bug report.
OpenShift currently ships phpMyAdmin-4.0.10.5 which fixes PMASA-2014-12 and all earlier issues. http://www.phpmyadmin.net/home_page/security/