Here I am thinking he may have exploited something in the new blog system... but it was just a mere upload to the pubaccess? How boring.
I'm experienced enough not to leave any stupid vulnerabilities in my code, but I gotta admit that I never thought of the extension issue that was used against us today. Even if it's badly configured Apache, which I'm not 100% sure of, it's really my mistake in the end.
Edit. Not trying to say that this guy isn't a fucking moron because he is.