Some older browsers are vulnerable to XSS attacks as such
Current versions of IE, FF, Chrome are
here you can find some XSS attacking vector http://ha.ckers.org/xss.html