So browsers start interpreting properly-escaped markup-lookalike as though it was actual markup? I don't think so. There is a web app bug here.
I think the description is not very clear about this step, I had to look at the source of the exploit page to understand what happens.