Since so many other websites have been hit I have to assume it is a bot!
It has injected a script with:
Yesterday: http://google-stats50.info/ur.php
Today: http://google-stats49.info/ur.php
It injected it into multiple tables.
First, how did it identify the tables and columns?
Second, what should I search for in the logs to identify the source page?
We do not have ftp on any of our servers. We have 1 contact form but it is email and not even connected to the database.
We are using SQL Server and IIS.