Defenses: <script> tags are stripped (case-insensitive regex).
<script>
The server removes <script> tags. Find another vector.