ExpressionEngine CMS
Open, Free, Amazing

Thread

This is an archived forum and the content is probably no longer relevant, but is provided here for posterity.

The active forums are here.

Stuff I didn't write being injected into CSS, possibly compromised

November 20, 2008 11:42am

Subscribe [5]
  • #16 / Nov 21, 2008 5:39pm

    fifteen

    108 posts

    Well, things have changed in the past 24 hours and I believe we may have plugged the hole. Some sort of PHP exploit was being used to do html insertion and we think it was WordPress. aSince updating to the latest version we have seen the problem go away. My thoughts on Freeform are that the exploit was capable of using forms - but that’s just a guess 😊

  • #17 / Nov 21, 2008 5:44pm

    Sue Crocker

    26054 posts

    Andy, so it looks like you were able to figure out what caused the initial problem. But is the Freeform problem solved now too?

  • #18 / Nov 21, 2008 5:45pm

    fifteen

    108 posts

    I don’t think freeform had much to do with it. I believe it was all Wordpress.

  • #19 / Nov 21, 2008 5:47pm

    Sue Crocker

    26054 posts

    In that case, since you know the problem was Wordpress, I’m going to close the thread. Don’t hesitate to post again if needed.

.(JavaScript must be enabled to view this email address)

ExpressionEngine News!

#eecms, #events, #releases