Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web script via (1) the strServer, cfg[BgcolorOne], or strServerChoice parameters in selectserver.lib.php, (2) the bgcolor or rowno parameters in displaytbllinks.lib.php, the leftfontfamily parameter in themeleft.css.php, or the rightfontfamily parameter in theme_right.css.php.