also #fragments aren't sent to the server at all, unless this changes that (a major major change if so)
So website with bad script injected is loaded by the user and is able to make requests to a logged-in banking website with time-based/scrolling attacks.