reflected xss in a javascript url with some characters blocked - how to test for reflected xss