Google's noteworthy antispam engineer Matt Cutts discussed the issue of cross-site scripting (XSS) flaws, as vulnerable sites have infected pages popping up in the dominant search engine's results pages. Failing to sanitize input properly with one's web application could lead to XSS exploits on the pages displayed by your website. These pages also find their way into search engines like Google, potentially exposing them to an even broader audience. When that happens, visitors to those pages may be connected to malware downloads. Such malware may steal personal information from the corrupted machine, or make it a node on a botnet for the purpose of attacking or spamming others.
More...