Debian Security Advisory 1675-1 – Masako Oono discovered that phpMyAdmin, a web-based administration interface for MySQL, insufficiently sanitises input allowing a remote attacker to gather sensitive data through cross site scripting, provided that the user uses the Internet Explorer web browser.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/72460/dsa-1675-1.txt
Source: https://packetstormsecurity.com/files/72460/Debian-Linux-Security-Advisory-1675-1.html