DOM XSS in innerHTML sink using source location.search. document.write() deletes all existing HTML