Security Monkey published a good case study about evidence seizure and what happens, if you forget to asses all relevant system data after a security incident occurs.
WordPress security warning! “If you downloaded WordPress 2.1.1 from wordpress.org within the past 3-4 days, your files may include a security exploit that was added by a cracker, and you should upgrade all of your files to 2.1.2 immediately”. Please check
Upgrading to wordpress 2.1.1 was urgent, but we still have SQL injections, path disclosures and cross site scripting problems in this version! My colleague Sebastian Krause has some examples: