This sounds like the most plausible scenario in which this bug can cause havoc. Even if the web server is quickly restored to its original state, any user who happened to connect at the wrong time may still have a compromised PC.
And you may not even notice that the web server has been compromised until compromised PCs start acting up.