6
On a XOOPS site i took over administration of i found a disabled module called cjaycontent in wich some scriptciddies was able to upload files to the server even it was disabled. had to delete the modulefolder
The file they uploaded to /tmp edited and added a ifame on every html and php file that had chmdod 777 or was owned by nobody on the whole server so yea, that wasted some time for us. think it was maybe 30 sites affected that time
So if you have cjaycontent or other module with uploading stuff, try if you can reach the uploading files without being logged in.