If you had sql injection rights in the database, there would be no need to trade; you would just insert a few nice rows in the db for yourself, mark yourself 'super trusted' and then initiate a withdrawal. This wasn't a SQL injection attack in my opinion.