Via post, we can send malicious code in order to steal cookies, access to sensitive information, do a web application defacement to every single user that visits the poisoned profile.
Disclosure Timeline:
10/13/2012 to: info () dokeos com
10/23/2012 to: sales.us () dokeos com
10/30/2012 No response, disclosure