XSS in MSIE using NUL byte, thanks to JPCERT.