how to test cross site scripting