I had something similar happen several years ago where every index page on the server was infected with an iframe. My host was able to quickly kill all occurrences but we never did trace exactly how they got in to plant it for sure. I was running a custom PHP script so we speculated that their was a vulnerability but it was not attacked again. We also speculated that it could have possibly happened when reviewing a submission that was infected and then it somehow went through the local PCs FTP client to the server.
I think I would make sure that your CMS is up to date or still being updated by the script writer to avoid it recurring.
__________________
Want a Sponsor that really PAYS?!?!?!?!
I&C#Q 3-0/2 7+3.3 0=5|2
|