This Vulnerability works even when you put your script (<img src="javascript:alert('Executed from ' + top.location)" >) in nickname and you can insert HTML codes in Nickname and Lastname.