Originally Posted by
contink
No offense to those who've commented before but generally it's not a good idea to assume that it's just a single point of entry and you've fixed it.
Once someone has got into your site (however they did it), you should assume that attempts have been made to subvert more than just a single page (rootkits, etc) and request your webhost do a thorough security scan of the account (and host environment).
I'd definitely get your joomla upgraded to the latest version as soon as possible and as suggested get yourself subscribed to the security watch list.
Also worth asking your host if mod_security is installed and asking them to include rules to cover common joomla and other PHP exploits.
good luck