Earlier quoted context omitted.
This is absolutely not how the Mt. Gox database works. I know because I have access to the source code of the site. All that source code you're looking at means nothing if the attacker gained arbitrary SQL execution on the database.
If you had sql injection rights in the database, there would be no need to trade; you would just insert a few nice rows in the db for yourself, mark yourself 'super trusted' and then initiate a withdrawal. This wasn't a SQL injection attack in my opinion.
What if he were in it to destroy Mt. Gox, as they say, "for the lulz"?
Making all their customers angry and causing a run on their escrow accounts might just do it more effectively than trying to withdraw whatever could be obtained through their online trading platform.