1. Given the context I'm sure that more people are going to run a JDB than who are going to get infected by public (patched) exploits such as CVE-2012-0507/CVE-2011-3544.
2. I didn't get their vulnerabilities detected and nor did I use a loadfile/dumpfile/outfile exploit to upload my shell but since you knew this was possible I'm guessing you're familiar with the site.
I assume that the vulnerabilities were detected because idiots thought it was funny to deface parts of their site and email the admin threatening to delete their database if they weren't given money.
You obviously know your stuff, but there's no need to be a dick.