It's actually inserting the script call into the database as well, so when you pull up a post, the script call will be in there even after the exploit has been removed. What is odd on this part is its only putting it into the POST_BODY field, not the POST_DEFAULT_BODY, so it doesn't seem it's being inserted via the normal add post method.