Wow, you've had some crazy people attempting to hit you this week, Aerosmith.
The good news is, they've both been through PHP, which is harden-able.
From what I can tell, that is a PHP exploit script that works by hacking you via a comments page. It has suspicious items like magicquotes, fsocksopen, etc. that a regular comment wouldn't have.

I'd take this time to make sure the page they're trying to run this through is as secure as possible.