A good FAQ about Cross Site Scripting...

http://www.cgisecurity.com/articles/xss-faq.shtml

What else is there to say?