Redirecting you to Reddit in 5 seconds:
https://old.reddit.com/r/netsec/comments/1bt622w/bypassing_dompurify_with_good_old_xml