I recently got this information from a security friend of mine. Spammers php to send spam, this means they can send spam from any php enabled webhost they have access. Keep and eye on those webservers.
posted below is the code
!DO NOT RUN ON YOUR WEBSERVER!
http://digitalparanoid.com/~matt/voxx.phps
Comments
spam through websites (cgi & php)
has been around since formail by Matt Wright....oh say 1997 or so :)
Contact forms have enormous vulnerability issues. A tiny amount of RTFM can get around that issue with relative ease.
Also, please write your code in English, or don't expect meaningful comment internationally