// javascript: URIs even if encoding fails. desc: 'Most basic XSS — shows that script execution is possible. In a real attack, document.cookie would be exfiltrated ...