We recently examined a website built using Drupal CMS. Somehow it was hacked into and all PDF files in the website were replaced with the ones carrying viruses.
After some probing around, we found that it wasn't caused by any vulnerability inside the Drupal code. The hackers stole an admin account and changed the configuration, and then further altered the content.
The website had upload module (in core) enabled.
Recent comments
2 weeks 2 days ago
2 weeks 4 days ago
8 weeks 1 day ago
9 weeks 1 day ago
13 weeks 5 hours ago
13 weeks 2 days ago
15 weeks 1 day ago
15 weeks 1 day ago
15 weeks 1 day ago
16 weeks 3 days ago