[原文]Direct static code injection vulnerability in ticker.db.php in Chucky A. Ivey N.T. 1.1.0 allows remote administrators to insert arbitrary PHP code into the config file, which is included other N.T. scripts.
N.T. contains a flaw that may allow a malicious user to run arbitrary code. The issue is triggered due to ticker.db.php not properly sanitizing unspecified or unknown values. Arbitrary PHP code may be injected, which will be executed when the file is included. It is possible that the flaw may allow the execution of arbitrary commands resulting in a loss of integrity.
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.