In his empty posts, using Firefox, I see
QUOTE
'>
` style=background:url(javascript:alert())
and
QUOTE
'>` style=background:url(javascript:alert())
This is what I get when I view the source:
CODE
<span style="" http://aaaaa="`aaajpg'" border="0" alt="user posted image">'><br>` style=background:url(javascript:alert()) </span>
WTF?
IE seems to be parsing some JS that isn't even in a <script> tag... There's another bug for MS to fix