This effectively abandons the application’s original script and injects a
new one immediately after it. The attack works because browsers’ pars-
ing of HTML tags takes precedence over their parsing of embedded
JavaScript: