XSS ME! (vulnerable param: GET['xss'])

x
Allowed UAs: FF4+, IE9+, Chrome 12+, Opera 11.5+, Safari 5+
Did it? Mail me :)

List of Glory:

  1. @garethheyes solved it (2011-09-22) #bypass fixed (not in Safari 5.x though - buggy browser is buggy)
  2. @kinugawamasato solved it (2011-09-22) #bypass fixed
  3. @thewildcat solved it (2011-09-22) #bypass fixed
  4. @shafigullin solved it (2011-09-23) #bypass fixed
  5. @garethheyes solved it again. Three times. (2011-09-24) #bypass fixed
  6. @masa141421356 solved it twice (2011-11-29) #bypass fixed