To be fair they rejected it because his "report" consisted of a link to a profile where he claimed to have exploited the bug, without any explanation of what he actually did. If he had at least given a rough indication of what the exploit was I am sure they would have reacted differently.
my name is khalil shreateh.
i finished school with B.A degree in Infromation Systems .
i would like to report a bug in your main site (www.facebook.com) which i discovered it .
repro:
the bug allow facebook users to share links to other facebook users , i tested it on sarah.goodin wall and i got success post
link - > https://www.facebook.com/10151857333098885
-----End Original Message to Facebook-----
"
Your point being? He doesn't explain the exploit at all, he just gives them a link to some profile he claims to have exploited (which already violated their ToS).