You should be using a separate database server than your web server if you're going to be storing credit card numbers. The database server should not be accessible by any machine except a small whitelist of IPs that you've specified. That way when your webserver gets compromised, it will require some looking around to realize the database containing credit card numbers isn't there.
Most server compromises that I've seen have stayed local to the server - I'm not a security pro; but generally I've seen the server that got knocked over get messed around with, anything on that server was fair game.
Beyond that, I'm sure there are other things you should do to protect the database that contains the credit card numbers; but seriously - keep them off your web server.