Reflected XSS in a JavaScript URL with some characters blocked - Explaining the Payload