We recently examined a website built using Drupal CMS. Somehow it was hacked into and all PDF files in the website were replaced with the ones carrying viruses.
After some probing around, we found that it wasn't caused by any vulnerability inside the Drupal code. The hackers stole an admin account and changed the configuration, and then further altered the content.
The website had upload module (in core) enabled.
Recent comments
8 weeks 4 days ago
9 weeks 3 days ago
20 weeks 3 days ago
21 weeks 6 days ago
30 weeks 4 days ago
30 weeks 5 days ago
31 weeks 5 days ago
32 weeks 4 days ago
32 weeks 4 days ago
32 weeks 5 days ago