Thanks.
Perhaps we can have our host restrict browsing in the attachments folder (which is in side the httpdocs--document root, making it accessible through http)
--------------- Added [DATE]1330925858[/DATE] at [TIME]1330925858[/TIME] ---------------
A little more investigation led me here:
https://www.vbulletin.com/forum/show...t-please-check
That script is similar to the one we found on our site (twice).
We've put .htaccess files in the custom* directories, as well as the root of the attachments directory. Hopefully that will deny all future access to injected PHP on the forum.
Thanks again,
F