It doesn't really look like there was any attack. One of the developers made a mistake with the PHP opening tag in the config file. Anyone visiting the page would have seen this output.
there are dozens of pages that have been exposed on this one server. I have no idea how the opening tag can get mangled in so many different files
By having a central config file that is included throughout the pages. Once included, it's not parsing it as PHP because it has the typo in it - thus showing it on all pages that include that file...
If the typo is in a top-level layout file or something that would happen.