Spam PHP files appearing under /files/cache

Permalink
I noticed yesterday that php files linking to spam websites were being uploaded onto my website, here:

http://www.thestables-orcasisland.com/files/cache/...

Most of the files uploaded have 'zend_cache' incorporated into their name.

How did this happen? What can I do to stop this?

Is this a vulnerability in my version of php:

http://www.thestables-orcasisland.com/files/cache/asdf.php...

Thanks

 
mkly replied on at Permalink Reply
mkly
Hello,
Could you post a couple of the file names that have the spam links int them? The ones containing "zend_cache".
masonrobison replied on at Permalink Reply
Here are some file names:

/files/cache/zend_cache---e8ea0a0fa431cc2e54e19cb90188a85a49a3e9f2128c99176d7e7d7da056a777

/files/cache/zend_cache---internal-metadatas---e8ea0a0fa431cc2e54e19cb90188a85a49a3e9f2128c99176d7e7d7da056a777

There were over 1000 of these files uploaded. I deleted most of them. It appears that they have stopped being uploaded.

I spoke with the person who informed me of this problem. He said that he received the link in a spam email and traced it back to my website.