The way he was able to add his key was via a web-based exploit, which effectively gave him administrative web access. So yes, the list is correct.
This bug allowed one to add their public key to another user's account, and make changes to comments and issues.