CVE-2006-1746
Directory traversal vulnerability in PHPList 2.10.2 and earlier allows remote attackers to include arbitrary local files via the (1) GLOBALS[database_module] or (2) GLOBALS[language_module] parameters, which overwrite the underlying $GLOBALS variable.
Date published : 2006-04-12
http://www.securityfocus.com/bid/17429
http://www.securityfocus.com/archive/1/430475/30/30/threaded