Cross-site scripting/character encoding demo

When interpreted under most character encodings, the following line appears to contain gibberish, but note that it doesn't contain any characters that are 'special' in HTML (apart from the <p> and </p> tags at the start and end if you do a 'View Source'). But if you set your browser to interpret this page in UTF-7 you'll find that the line DOES contain HTML tags. Now think what could have been achieved if they had been script tags...

Just to say +ADwA-b+AD4A-BOO+ADwA-/b+AD4A-!