well I gotta ask. Couldn't this, (and most likely) be a XSS attack. I dont know if they comprimised root... On you web page(s), do you use any .php or .asp or anything similarily dynamic ? Are you sure it was an 'uploaded' page and not XSS ?