Somebody entered XSS code in my friend's site. It inserts <script>alert(0)</script> in the page source. You can see it here.
Is there a way to remove this from the page at runtime, to prevent it from being executed?
He has a presentation on it tomorrow and he has no access to database to remove it.
<body>element?