I tried entering in a meta redirect into the mix, also tried to embed a video, and no go... so Im doubting this can be used maliciously.
vB already does a good job at preventing malicious scripts from being entered in as profile fields as the meta redirect I put in when I looked at the page source shown this:
Code:
<meta http-equiv="refresh" content="2;url=http://www.google.com">
So I think there is nothing to worry about here, again, unless I am missing something...