They weren't publicly facing, but the website was just a very thin wrapper that exposed a SAS server (I believe) to queries from the internet.
And if you are at all familiar with SAS, you will understand how trivial command injection is.