An issue in onethink v.1.1 allows a remote malicious user to execute arbitrary code via a crafted script to the AddonsController.class.php component.