Personally, I'm thinking of just not allowing "attachment uploads" until this is resolved... That would prevent the uploading of the .js files, but I'm not sure how they were able to inject the code into the database to begin with. That is obviously what worries me.