This strict URL filter should prevent XSS, right?

Medium Cross Site Scripting (XSS)

This one is pretty simple. One parameter is vulnerable, ?url=. Can you get XSS to execute?


Solution