I believe you are right, but I believe they where trying this attack against Cold Fusion since that webserver is running Cold Fusion and not PHP. I believe those sites that where in the logs are some form of anonymoizer (sp?), for them to cover their tracks.