Bringing MySQL to the web


Announcement-ID: PMASA-2011-19

Date: 2011-12-21


XSS in setup.


Crafted values entered in the setup interface can produce XSS; also, if the config directory exists and is writeable, the XSS payload can be saved to this directory.


We consider this vulnerability to be non critical.

Mitigation factor

The documentation warns against leaving this directory writeable; also a warning appears on the home page. Also, this XSS would target only the users who visit /setup.

Affected Versions

Versions 3.4.x are affected.


Upgrade to phpMyAdmin 3.4.9 or newer or apply the related patch listed below.


Thanks to Jason Leyrer of Trustwave SpiderLabs for finding this issue and to Robert Foggia (same company) for contacting us.

Assigned CVE ids: CVE-2011-4782

CWE ids: CWE-661 CWE-79


The following commits have been made to fix this issue:

More information

For further information and in case of questions, please contact the phpMyAdmin team. Our website is