PHP remote file inclusion vulnerability in Tutti Nova 1.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the TNLIB_DIR parameter to novalib/class.novaEdit.mysql.php.
https://www.exploit-db.com/exploits/2220
https://exchange.xforce.ibmcloud.com/vulnerabilities/28471