Description
phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to execute arbitrary commands via shell metacharacters.
Remediation
References
Related Vulnerabilities
Nginx Memory Allocation with Excessive Size Value Vulnerability (CVE-2026-49975)
Next.js Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2026-27978)
WordPress Plugin Thrive Clever Widgets Security Bypass (1.56)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-0361)
WordPress Plugin GiveWP-Donation and Fundraising Platform Cross-Site Scripting (2.3.0)