I think that alongside the current rules a new rule should be created making it bannable or a high warning if a member conducts vulnerbility scans on the site/server. I suggest this as it could be seen as not covered by the the do not hack iE/members rule.
Also any possible vulnerbilities discovered whilst on iexploit.org should be reported to Admin/staff through PM instead of being posted openly on the forum.
The following could be a template for anyone wishing to PM admins about one.
Good idea i will implement this, i will also arrange a bounty where if you find a vulnerability and report it before taking advantage of it i will pay you