SELinux saved my ass years ago, preventing exploitation of an outdated/vulnerable PHP application. Since then, it gets installed on every production server I deploy. Those who simply turn it off because it's a PITA are doing themselves a huge disservice.
An outdated version of a PHP application (which had a public vulnerability) was attacked, allowing arbitrary code execution. The "exploit" attempted to download and execute a remote file via TFTP. Ultimately, a "remote shell" would end up being installed on the server.
SELinux, however, prevented the TFTP transfer from happening. We saw this in the audit logs, investigated, and discovered what had happened (and, of course, updated the PHP application).
If the attack had succeeded, I'm convinced that it eventually would have ended up as a full ("root-level") compromise.
[1]: http://en.wikipedia.org/wiki/Security-Enhanced_Linux#Overvie...