Haha, you can trust me, people (evil-grin)."XSS has been around for a long time, but the current appetite for weblogs opens up new opportunities for attackers.The idea is simple: a web site allows users to enter content. Somehow, the third party content gets embedded in an HTML page at the server before it is sent out to other users. Lots of sites rely on this principle: Amazon, eBay, Yahoo Groups and, of course, web logs.
What happens if the posted content contains a script? Well, you may have seen what happens: the script gets executed on your machine."