I'd guess that it didn't rely on the security of a web server, but the entry point was the "thin end of the wedge" for probing and deploying more sophisticated attacks.
At some point, the front end of any web application has to go to the back end database to get information. So there's just no way to cleanly and completely isolate the front facing parts of an application from possible breach.