Api.ning.com

I actually used a similar attack vector against a several separate real world XSS filters by using the conversion filter itself (here is an example) to help create the attack vector (IE: "java	script:" was converted into "java script:", which renders … ................
................