A few weeks ago I saw a vulnerability reported for an FTP server that claimed they could put a file on the remote server. With FTP! What madness! I wish I could find it but I cannot, still makes me chuckle.
Yeah, we get those too. We let people write JavaScript to build their sites (we're a site builder), and people will use that feature and add an alert and then claim it's XSS (on their own account).