<input type=hidden name=foo value=<?php echo $_GET['foo']/>
<a href="/foo" onclick="location.href='/sq?arg=foo'+alert('xss_check')//'">
foo.innerHTML = document.location.href;