4. DOM-Based XSS

Message

Script Used

<script>
   var url = document.location;
   url = unescape(url);
   var message = url.substring(url.indexOf('message=') + 8, url.length);
   document.write(message); 
</script>