How about some real-world, application specific exploits?

There's an example of a XSS that can be used to compromise Cisco Web VPN
session in the text.

So, please show me an example of an actual compromise and I'll listen.
Otherwise, put up, or shut up!

You're not strictly required to listen, you know ;)