Re: Kasia is not nuts really - She made the Register!
BlueBear this is quite a common practice although there are means of protecting oneself from this type of exploit.
Although I am not fully up to par as it relates to it's practices and security measures you may find a great many more details at this Web Page. (XSS Details)