Im pretty sure they used the exploit described below, I just hadn't installed the patch. I would still like to better understand how it was done, maybe even try it on myself when the backup is installed again.
"A flaw within a side query that is used in the search UI has recently been discovered that affects all versions of vBulletin 4 Forum Classic and vBulletin 4 Publishing Suite. This flaw may enable malicious individuals to inject sql that would allow you to run arbitrary queries on the db via this exploit. To resolve this issue, it has been necessary to release a patch level version on all versions of vBulletin 4.X. "
|