> I'd be interested to know if
> anyone can confirm/reject my guess that the site has been hijacked.
It's an exploit called c99shell. It's been around a while, but will still
hit any PHP server that allows execution from its upload area.
http://www.google.co.uk/search?q=c99shell+%22uname+-a%22 for a rather
worrying set of results - and note that many of those exploits are still
live :-(