A security advisory issued by Drupal assumes that every installation of the popular CMS based in the version 7.x was compromised unless patched. Attackers may have created backdoor in the system which could allow them to control the target and compromise other services on the server. The Development Team at Drupal confirmed that the attacks started within hours of the public disclosure of the vulnerability occurred on October 15th. The US-CERT has also issued a security advisory on the vulnerability on the same issue. The recommendation is to restore from backup or rebuild the site from scratch.”]
Source: http://securityaffairs.co/wordpress/29736/cyber-crime/drupal-critical-sql-injection.html

