What a cluster... ...mess.
It gives enough access for the hacker to gain access elsewhere and then install other backdoors in more obscure places... so how do you recover from it? It's not enough to just patch.
For Drupageddon, the "easy" solution if you had a recent backup was to burn down the server and reinstall everything from source or backups from before the earliest known use of the exploit. I can't imagine how you pull that off on a very complex system.