Even before Samy became everyone's hero, I discovered the same bug at social sites as he had. I wrote a proof-of-concept hack that forced people to change their preferences if they just clicked a plain normal link I gave them. Some sites changed their structure at my warning, I even wrote this
Forced Post Vulnerability Report about it.