Debian Security Advisory 1403-1 – Omer Singer of the DigiTrust Group discovered several vulnerabilities in phpMyAdmin, an application to administrate MySQL over the WWW. phpMyAdmin allows a remote attacker to inject arbitrary web script or HTML in the context of a logged in user’s session (cross site scripting). phpMyAdmin, when accessed by a browser that does not URL-encode requests, allows remote attackers to inject arbitrary web script or HTML via the query string.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/60803/dsa-1403-1.txt
Source: https://packetstormsecurity.com/files/60803/Debian-Linux-Security-Advisory-1403-1.html