It was possible to conduct an XSS attack via a crafted SQL bookmark.
We consider this vulnerability to be serious.
For 2.11.x: versions are not affected.
For 3.x: All 3.x releases on which the "bookmarks" feature is active are affected.
Upgrade to phpMyAdmin 126.96.36.199.
We wish to thank Sven Vetsch/Disenchant for informing us in a responsible manner. His site is http://disenchant.ch.
Assigned CVE ids: CVE-2009-2284
The following commits have been made to fix this issue:
For further information and in case of questions, please contact the phpMyAdmin team. Our website is phpmyadmin.net.