source: https://www.securityfocus.com/bid/2750/info eSafe Gateway is a security utility used for filtering internet content. An html file may be crafted to bypass the script-filtering feature offered by eSafe Gateway. This is done by simply changing the syntax of the If we run this page through eSafe's filtering engine, the script will be filtered and the resulting with the following HTML code: However, if we create the following code: language="javascript"> alert("hi"); Then the inner "" will be extracted and we will be left with the following HTML code: