A few months back there were an exploit found for osC that allows a hacker to upload files remotely to your server, through file_manager.php

This is a fast and simple fix! (1min install)

WhaCo

More...