The first site is also hosted in same hosting company you are with


Domain Name: BESTXPORNTUBE.COM
Registrar: MELBOURNE IT, LTD. D/B/A INTERNET NAMES WORLDWIDE
Whois Server: whois.melbourneit.com
Referral URL: http://www.melbourneit.com
Name Server: NS37.CIRTEXHOSTING.COM
Name Server: NS38.CIRTEXHOSTING.COM
Status: clientTransferProhibited
Updated Date: 10-apr-2007
Creation Date: 02-apr-2007
Expiration Date: 02-apr-2008
I guess the hacker have an account in same server, not sure if php open base dir is enabled on your server, if not other sites on the server can access files with 777 permission on your server and modify config.php (this file have 777 permission).

You can check your config.php to verify this. If this is what happend, that is not a script problem, it is server security, you should enable open_base_dir on your server, contact server admin to do that.