Iam trying to made a list about how many ways XSS can be dangerous to prove some people that is important to filter XSS attacks. If You have some idea - add it. For example:
1 - Cookie based authentication stealing,
2 - CSRF,
3 - ... ?
- SEO link injection e.g. boost PR.
- Dossing webpages with XSS e.g. shutdown access.
- Worm canning e.g. storing worms
- Privacy infringement
- Makes you look like an amature, n00b programmer.