window.name survives navigations, so an attacker page can set it then redirect here. JS does out.innerHTML = window.name. Test: run name='<img src=x onerror=alert(document.domain)>';location='/dom/windowname' in the console of any page.
RatXSS Dojo · HackXpert Coaching · The XSS Rat · authorized lab use only