JavaScript : XSS protection is disabled