I'm surprised this is so common. I've never set up any database accessible to the public-- I've already got to worry about securing the public-facing web server, why add another vector for attack?
And to be fair: http://www.shodanhq.com/search?q=mysql