There have been no reports of this mod being the source of any exploits.
Keep in mind that a directory being 777 doesn't mean anyone can inject scripts into it from any server - the attacker needs some form of access to your server via other means (either an Admin account with Can Admin Plugins) or another account on the server.
That still doesn't mean anyone else on a shared server can hack your site - there's still open_basedir restrictions which any shared host worth their salt would have enabled.
Fillip
|