Is there anyway to bypass WAF to trigger XSS if any letter after < is blocked?
Eg. < script> works but <script> is blocked.