XSS with $(location.hash)
demo
Click this
link
.
Verified on FF, Chrome, Safari + IE9/10