OsCommerce can send out spam via the Mailinglist function, without login.
osCommerce Online Merchant v2.2 RC2a has bug where one can send out spam through
http://domain.com/admin/mail.php/login.php
The proposed fix for oscmax is:
The fix in OscMax is:
http://code.google.com/p/oscmax2/source/detail?r=169
Also what is going on with these files here:
http://www.oscmax.com/blog/michael_s/security_notice_oscmax_204_released


