Dynamic variable evaluation vulnerability in lists/admin.php in phpList 2.10.8 and earlier, when registerglobals is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the SERVER[ConfigFile] parameter to admin/index.php.
phplist before 2.10.8 allows remote attackers to include files via unknown vectors, related to a "local file include vulnerability."
Multiple cross-site scripting (XSS) vulnerabilities in phplist before 2.10.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Directory traversal vulnerability in PHPList 2.10.2 and earlier allows remote attackers to include arbitrary local files via the (1) GLOBALS[databasemodule] or (2) GLOBALS[languagemodule] parameters, which overwrite the underlying $GLOBALS variable.