Evo version?
Check last modified files in your site root
in the past I had a similar problem with iframe hack, there was some code in .htaccess
I am having the exact same problem. Just discovered it today.
@ homerjon & gibso80
Please supply:
Evo version + a list of ALL snippets used and or not used but are on the server
Without the information there is probably no chance anyone can offer help
I am using 1.0.14
Content
Ditto (10) - 2.1.1 Summarizes and lists pages to create blogs, catalogs, PR archives, bio listings and more
DocLister (26) - 2.1.30 Snippet to display the information of the tables by the description rules. The main goal - replacing Ditto and CatalogView
Jot (7) - 1.1.4 User comments with moderation and email subscription
phpthumb (24) - 1.2 PHPThumb creates thumbnails and altered images on the fly and caches them
Reflect (15) - 2.1.1 Generates date-based archives using Ditto
Forms
eForm (3) - 1.4.6 Robust form parser/processor with validation, multiple sending options, chunk/page support for forms and reports, and file uploads
Login
MemberCheck (13) - 1.1 Show chunks based on a logged in Web User's group membership
Personalize (8) - 2.1 Personalize snippet
WebChangePwd (14) - 1.0.1 Allows Web User to change their password from the front-end of the website
WebLogin (2) - 1.1.1 Allows webusers to login to protected pages in the website, supporting multiple user groups
WebSignup (12) - 1.1.1 Basic Web User account creation/signup system
Navigation
Breadcrumbs (1) - 1.0.5 Configurable breadcrumb page-trail navigation
FirstChildRedirect (9) - 2.0 Automatically redirects to the first child of a Container Resource
if (25) - 1.2 A simple conditional snippet. Allows for eq/neq/lt/gt/etc logic within templates, resources, chunks, etc.
ListIndexer (5) - 1.0.1 A flexible way to show the most recent Resources and other Resource lists
UltimateParent (11) - 2.0 Travels up the document tree from a specified document and returns its "ultimate" non-root parent
Wayfinder (4) - 2.0.4 Completely template-driven and highly flexible menu builder
Search
AjaxSearch (6) - 1.10.1 Ajax and non-Ajax search that supports results highlighting
I am not using any snippets that don't come standard out of the box.
I am seeing the exact same thing with 1.0.15 installed. Has anyone been able to discover the source of this security hole?
You might check for any plugins that use onwebpageprerender or onwebpagerender events, it could be added that way.
Thanks breezer. I was able to fix this by upgrading to 1.1. Still unsure of where the security hole is exactly.