1 2 3 4 5 6
<?php $photos = array( "name" => "</script><script>alert(\"xss\")</script>" ); ?> <script> App.photos = new Photos(<?php echo json_encode($photos); ?>); </script>
1 2 3
<script> App.photos = new Photos({"name":"<\/script><script>alert(\"xss\")<\/script>"}); </script>