Today, Hong emailed me with yet another Google XSS vulnerability. This time it is in the way Google
I find out a hole in Google Docs XSS filter. Google Docs does not know how textarea works, If we inject the following HTML code to the document.

The link for this article located at ha.ckers.org is no longer available.