An attacker can exploit this issue to overwrite variables in the global $_SESSION array with arbitrary data. This may aid in further attacks.
phpMyAdmin 3.4.0 is vulnerable; other versions may also be affected.
Vendor Status:
Currently we are not aware of any vendor-supplied patches