надо что бы полоучилось примерно:
javascript:alert('XSS')
это Long UTF-8 Unicode encoding without semicolons
This is also useful against people who decode against strings like $tmp_string =~ s/.*\&#(\d+);.*/$1/;