Cross-site scripting (XSS) vulnerability in scripts/setup.php in phpMyAdmin 2.11.1, when accessed by a browser that does not URL-encode requests, allows remote attackers to inject arbitrary web script or HTML via the query string.
| Software | From | Fixed in |
|---|---|---|
phpmyadmin / phpmyadmin
|
2.11.1 | 2.11.1.x |