SOURCE

console 命令行工具 X clear

                    
>
console
var xss = "xss\" onerror=\"javascript:alert('111')\"";
var img = "<img src=\""+xss+"\" />";

var test = document.getElementById('test');
test.innerHTML = img;
<div id="test"></div>