http://markmaunder.com/2011/08/02/technical-details-and-scri...
Props to Ben. When I worked with him to fix timthumb I don't recall him mentioning that it was someone else who wrote the bug.
There have been plenty of vulnerabilities just as bad or worse since - and it keeps our site cleaning team busy. Besides Timthumb, the other top WP vulnerabilities/exploits are Revolution slider, Mailpoet and Gravity Forms.
You rarely see a site hacked via an old timthumb these days but it still shows up. Most hacked sites are from the other three newer remote code exec vulns I mentioned.