> A lack of filtering on user CSV output that could allow an attacker to run arbitrary code on an administrator's computer. > Improper cookie invalidation that could allow an attacker to unset internal global variables. Those don't count as serious issues? Props to them for making the report public though.
> > A lack of filtering on user CSV output that could allow an attacker to run arbitrary code on an administrator's computer. Iff the user has Excel, and explicitly allows it to run macros in a CSV file. It's already a stretch to call this a phpMyAdmin vulnerability, much less a "medium severity" one. > > Improper cookie invalidation that could allow an attacker to unset internal global variables. From the PDF report…
In other words, "This project is too full of potential security holes to find the definite ones."