Cross-site scripting (XSS) vulnerability in import.php in phpMyAdmin before 4.1.7 allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename in an import action.
{ "binaries": [ { "binary_name": "phpmyadmin", "binary_version": "4:4.0.10-1ubuntu0.1+esm4" } ] }