XSS in location.hash example poc
Document Object Model Javascript Injection via location.hash