javascript:alert('hello') #### sub alert { print "javascript:alert('hello')\n\n"; } #### sub alert { $msg = shift; $msg =~ s/(\W)/sprintf("%%%x", ord($1))/eg; print $query->header(-script=>"alert('$msg')"); }