Bypass XSS filtering rules
I believe we all have this experience when doing * testing. There is obviously a XSS vulnerability, but there are XSS filtering rules or WAF protection that prevent us from successfully exploiting it. For example, if we type alert ("hi"), it will be converted to alert (> xss detected).