I am running EE 1.6.3. on a public-facing website. We have a paid EE license, which I can provide the key if needed.
Recently, I noticed a bunch of users in my “members” table that should not be there. One was even a superadmin. I have not configured the site to allow for users to self-register, and even more disturbing one of these rogue members was listed as a SuperAdmin.
I am not the only superadmin on the site, but these were pretty clearly spam accounts (with names like Free Tax Advice and similar).
When looking in the CP logs, none of those rogue users showed up as having been created (so I assume they weren’t created via the CP UI), where accounts that I created do show up in the log. They also don’t show up as ever having logged in, though if they don’t show up as created either, I should probably assuem that the CP log is not infallible.
I deleted the rogue accoutns, and they have not come back in the 24 hrs since. I was not able to discern any malicious activity on the site, but I don’t know enough about digital forensics to be sure I didn’t miss something.
I’m extremely concerned that this site is now vulnerable, esp. since I didn’t see anything in the change logs of the later versions of EE after mine to indicate that a SQL inject bug of this magnitude has been found and squashed.