An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file.