Reflected XSS in a JavaScript URL