Did you ever find a form worst than this one ?
In a quick note from Ilia Alshnetsky, "To all the people who carelessly claim that Cross Site Scripting (XSS) is not a real security problem here is definitive proof that the threat is quite real. A very creative user of MySpace, Samy created a little self propogating worm via a stored XSS attack."