Hi people i've been hacked through that security hole in tiny_mce:
92.63.104.34 - - [09/Nov/2011:07:57:00 -0300] "POST /zenphoto/zp-core/zp-extensions/tiny_mce/plugins/ajaxfilemanager/inc/class.images.php?truecss=1 HTTP/1.1" 200 181 "-" "User-Agent: Mozilla/5.0 (Windows; u; Windows nt 5.1; en-us; rv:1.9.1.5) gecko/20091102 firefox/3.5.5 gtb5"
82.146.43.62 - - [09/Nov/2011:18:28:38 -0300] "POST /zenphoto/zp-core/zp-extensions/tiny_mce/plugins/ajaxfilemanager/inc/class.images.php?truecss=1 HTTP/1.1" 200 181 "-" "User-Agent: Mozilla/5.0 (Windows; u; Windows nt 5.1; en-us; rv:1.9.1.5) gecko/20091102 firefox/3.5.5 gtb5"
I had several POST attacks (it allows to upload files as i saw in (devilscoffee)
They've changed every single *.php /*.js files with a malicious code.
Also they've reach the .htaccess file and added some crazy rules to redirect.
Now i'm flagged by google, that hole killed my wordpress, joomla, zencart and zenphoto installations.
Now i'm trying to get back with all, this is a huge whole.