I just performed a quick test and indeed, the validator will not just 301 to other pages on the same domain but cross domains as well. So you could easily use it to trigger an event like hacking another site on your behalf.
- RSnake
Gotta love it.
http://ha.ckers.org