Another classic example, SELinux.[1]
[1]: http://en.wikipedia.org/wiki/Security-Enhanced_Linux#Overvie...
[1]: http://en.wikipedia.org/wiki/Security-Enhanced_Linux#Overvie...
SELinux, however, prevented the TFTP transfer from happening. We saw this in the audit logs, investigated, and discovered what had happened (and, of course, updated the PHP application).
If the attack had succeeded, I'm convinced that it eventually would have ended up as a full ("root-level") compromise.