Exploiting inconsistent UTF-8 handling in mbstring to bypass an XSS filter in Joomla ( www.sonarsource.com )