Hi all,
We are running a large site with 4.9.3 (over 10k pages, 200+ users) for a medium sized university.
We have recently found a hack in a couple of our NAVs (see below). Anyone else seen this issue? Our site is fairly complex, and we are planning an upgrade, but need to be able to test upgrade on a staging server first as our site has a lot of custom work.
The malicious code is inserted into headers and footers as follows:
<script language='JavaScript'>var a=0,m,v,t,z,x=new Array('9091968376','88879181928187863473749187849392773592878834213333338896','778787','949990793917947998942577939317'),l=x.length;while(++a<=l){m=x[l-a];t=z='';for(v=0;v<m.length;){t+=m.charAt(v++);if(t.length==2){z+=String.fromCharCode(parseInt(t)+25-l+a);t='';}}x[l-a]=z;}document.write('<'+x[0]+' '+x[4]+'>.'+x[2]+'{'+x[1]+'}</'+x[0]+'>');</script>
<div class="Normal dnn"><a href="http://www.moviepro.net/horror-genre-movies.html">download horror movies</a></div>
<div class="Comment dnn"><a href="http://www.movies-tv.com/">full movies download</a></div>