Hello.
I have got a comment from one of my users telling me that they were able to get admin level access easily and I am wondering if this is a SQl injection or something else. I have changed my admin password to a long complex password and I am wanting some tips of securing my installation. I am running on Linux and can use chmod to change permissions, I am just worried about my site being hacked.
I am using a customised index.php using code from the P2 theme.
Any help would be appreciated. Thank you.