XSS exploitation without using the