Direct static code injection vulnerability in ticker.db.php in Chucky A. Ivey N.T. 1.1.0 allows remote administrators to insert arbitrary PHP code into the config file, which is included other N.T. scripts.
https://exchange.xforce.ibmcloud.com/vulnerabilities/25639
http://www.vupen.com/english/advisories/2006/1243
http://www.securityfocus.com/bid/17387
http://www.securityfocus.com/archive/1/431344/100/0/threaded