SynopsisThe remote web server hosts a PHP application that is affected by multiple cross-site scripting vulnerabilities.
DescriptionAccording to its self-identified version number, the phpMyAdmin 3.5.x install hosted on the remote web server is earlier than 3.5.8 and is, therefore, affected by multiple cross-site scripting vulnerabilities. The flaw exists in the 'visualizationSettings[width]' and 'visualizationSettings[height]' parameters of the 'tls_gis_visualization.php' script. An unauthenticated, remote attacker, exploiting this flaw, could execute arbitrary script code in a user's browser.
SolutionEither upgrade to phpMyAdmin 3.5.8 or later, or apply the patches from the referenced link.