Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.0.1 allows remote attackers to inject arbitrary web script or HTML via the set_theme parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/25305
http://www.vupen.com/english/advisories/2006/0991
http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0