It doesn't quite belong here ... but CERT has published a short overview of Cross Site Scripting and what you can do to avoid it:

CERT CSS overview

Cheers,

BrainStop