1) You could invite anyone to a Facebook event via their Facebook ID by simply doing an HTTP post of Facebook ID's to the event invitation script on this domain, but not on the main site. For some reason, on the mobile site they didn't implement the check to see if you were actually friends with the invitee. Since FB sends an email to each invitee, this was an enormous spamming loophole for quite a while.
2) For a long time, there was no frame-breaking script on m.facebook.com. You could clickjack essentially anything on Facebook this way. Years ago I did a proof-of-concept on this where I clickjacked a platform app authorization, which let me receive the name, email, and other profile info of any user that did nothing more than click the X button on an annoying overlay I put on the screen.