Reflected XSS in a JavaScript URL with some characters blocked