OUCH. If you maintain the moving parts of server infrastructure that you expose to the world, you'd better know how to mitigate this kind of issue.
http://www.zdnet.com/article/update-drupal-asap-over-a-million-sites-can-be-easily-hacked-by-any-visitor/