In PHP, you could log your victim's IP address, but PHP's uses for malware are somewhat limited due to it being server-side, but you can still have some fun.
In JavaScript, you can do some VERY nasty things, Google around for some JS viruses.
You could create a Java-drive-by, which will download-and-execute a file without the user knowing, provided they click the "allow applet" button, but you could fool horny men into running it by making it look like a cam site.
The possibilities are endless, you just need some creativity and some programming knowledge.
NoScript is a must, it will stop any JavaScript.