It actually all happened on my friends forum, we had a hated (ex-staff) and some how he was able to do something with SMF, via a SQL injection to delete all post, change the boards name, description, change everyone to member's and change the themes settings. They SAY (SMF) its a picture SQL injection (people naming EXE's as Pics and uploading then running them to gain access) but i patched it via a post a staff member made (i don't know where it was) but even when i did that it didn't work and they still were able to change everything