phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to execute arbitrary commands via shell metacharacters.
https://exchange.xforce.ibmcloud.com/vulnerabilities/18441
https://euvd.enisa.europa.eu/vulnerability/EUVD-2004-1145