Defenses: <script> tags stripped. Common event handlers (onerror, onload, onclick, onmouseover, onfocus, onblur, oninput, onchange, onsubmit, onkeydown, onkeyup, onkeypress) are stripped.
<script>
onerror, onload, onclick, onmouseover, onfocus, onblur, oninput, onchange, onsubmit, onkeydown, onkeyup, onkeypress
Common event handlers are stripped. Find an obscure one.