No, I think you have missed the point of the post.
If I wrote a script in javascript and placed it in a web post and the user loaded the web post in his or her browser it would run in that post like it was taken from that site.
Now you can not read cookies across web domains but if added to a post on that web domain you can use a hidden javascript to read the viewers user name and pass code from that domain name. Then if that script sent that information without you knowing it to another place that just logged all that information for future retrieval by someone that implanted the script they can use your log in information to be you.
Allowing users to load web pages into a forum like this is a disaster waiting to happen. Also the use of HTML in a web forum is also a disaster waiting to happen for many more reasons.
Not everyone out there is honest and or trustworthy. Give them a change to do harm to your site or board and they will take it if they are that type of person. I guarantee it. It is your site, do what you want. But if you do and someone is evil enough to take advantage of you and your allowing HTML or web pages in posts and your site is hijacked please don't come back and give the expression you were "hacked".