Here's a way to by bypass that- point the FF dev tools soley at the iframe, then use the scratchpad to run the alert. It will accept that and let you move past.
I spent 20 minutes thinking I had something horribly wrong until I read this comment.
Even percent-encoding it ends up just including the entire injection as the path (on 50.0). I worked around it for now by editing the element directly in Developer Tools.
You're right. It still works in Chrome though...
If someone has trouble making the exploit work in Chrome: The developer tools replace all ' with " if you inspect the element. Therefore, it misleads you into thinking that the website encloses attributes in " ", whereas instead it is enclosed in ' '.