I saw this advisory linked over on Slashdot for vulenabilities in php xml-rpc libraries used in a lot of blogging packages:
http://news.netcraft.com/archives/20..._exploits.html
The xml-rpc library in phpAdsNew is also vulnerable:
http://phpadsnew.com/two/nucleus/index.php
The good news is that you can protect phpAdsNew right now by simply deleting or moving a single file if you don't feel comfortable installing the upgrade on your own.