Instead of
onclick="alert(" hi')'=""
, it should be
onclick="alert('hi')"
. Anyway, 1) using
alert
in production is a bad idea, 2)
alert
doesn't provide a way for user confirmation.
Better use, for example, jQuery dialog:
http://jqueryui.com/dialog[
^].
DOM manipulation also should be done more accurately. Even if yours works, it makes the functionality poorly supportable, because it depends too much on existing content and your
exp
. It would be more reliable to take a node found by its order, remove it, and replace what you need (I don't know why though). Please refer to
http://api.jquery.com/category/manipulation[
^].
—SA