I'd also recommend banning document.cookie and window.change, both of which are JavaScript operators... apparently there's a way to get people's passwords with document.cookie, although I'm not sure if vB2.3.0 is vulnerable to that anymore (but there was a big problem with it on Kraptastica awhile back... I think it's still in their Drama Archive), and window.change is how Jacques and his buddies managed to execute that window-opening script in the first plcae, or so I'm informed.

That's really hardly an exhaustive list of terms that can be used maliciously, but it'd be a good start. I've banned both of them, anyway :P