And it's not as sexy, but if you can control the format string you can also inject things like SQL commands or HTTP headers into a convenient place. It's basically just an input validation exploit that in the right circumstances leads to other attacks.