I got this from my host
Hi Mick,
Are you using the microcart installation?
This has a file management tool kcfinder which has many known security
vulnerabilities.
http://www.tooraktimes.com.au/microc...der/browse.php -> allows you to
upload and browse the files in public_html/microcart/kcfinder/upload/files
directory.
Check this link
http://packetstormsecurity.com/files...ll-Upload.html
The hacker uploaded a shell script and tried to scan all other configuration
files in the server. I am disabling that microcart link.
root@experience [/usr/local/maldetect/sess]# more
session.hits.052214-1739.1040785
{HEX}gzbase64.inject.unclassed.15 :
public_html/microcart/kcfinder/upload/files/b.php5