Damien Guard has a really good post on injection attacks. Worth a good read.

How dangerous is HTML injection?