For instance, a script that sets the location of a web page will make the browser redirect to the location specified: <script>location="";</script> ?
The src attribute of the HTML <script> tag allows you to load JavaScript from an external source. This piece of malicious code will execute the contents of on the victim’s browser during an XSS attack: <script src=></script>

<img onload=alert('The image has been loaded!') src="example.png">
类似地,onclick event属性指定在单击元素时要执行的脚本,onerror指定在加载元素时出错时要运行的脚本。如果可以在这些属性中插入代码,甚至可以在HTML标记中添加新的事件属性,那么就可以创建XSS。