Blast from the Past: Cross Site Scripting on the AWS Console
embracethered.com
embracethered.com
User input also shows up in surprising locations such as dns records and whois info.
Luckily, an effective xss attack e.g. targetting the admin of a target website, often require a large amount of effort and social engineering.
For persistent attacks, its mostly just sit and wait for an attacker - they don't really control when/if a user visits the compromised page.