CVE-2008-2960

Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.11.7, when register_globals is enabled and .htaccess support is disabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving scripts in libraries/.

Date published : 2008-07-02

http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0

http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2008-4